First published: Fri Aug 11 2023(Updated: )
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the `BadParamException` thrown by Fast CDR is not caught in Fast DDS. This can remotely crash any Fast DDS process. Versions 2.10.0 and 2.6.5 contain a patch for this issue.
Credit: security-advisories@github.com security-advisories@github.com security-advisories@github.com
Affected Software | Affected Version | How to fix |
---|---|---|
ubuntu/fastdds | <2.10.1+ | 2.10.1+ |
ubuntu/fastdds | <2.5.0+ | 2.5.0+ |
ubuntu/fastdds | <2.9.1+ | 2.9.1+ |
eprosima Fast DDS | >=2.6.0<2.6.5 | |
eprosima Fast DDS | =2.10.0-rc1 | |
Debian Debian Linux | =11.0 | |
Debian Debian Linux | =12.0 | |
>=2.6.0<2.6.5 | ||
=2.10.0-rc1 | ||
=11.0 | ||
=12.0 | ||
debian/fastdds | 2.1.0+ds-9+deb11u1 2.9.1+ds-1+deb12u2 2.11.2+ds-6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39948 is a vulnerability in eprosima Fast DDS that can remotely crash any Fast DDS process prior to versions 2.10.0 and 2.6.5.
CVE-2023-39948 has a severity rating of 7.5 (High).
CVE-2023-39948 affects eprosima Fast DDS versions prior to 2.10.0 and 2.6.5.
CVE-2023-39948 can be exploited remotely to crash any Fast DDS process.
To fix CVE-2023-39948, it is recommended to update to version 2.10.0 or 2.6.5 of eprosima Fast DDS.