CVE-2023-39948: Uncaught fastcdr exception (Unexpected CDR type received) crashing fastdds
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the BadParamException thrown by Fast CDR is not caught in Fast DDS. This can remotely crash any Fast DDS process. Versions 2.10.0 and 2.6.5 contain a patch for this issue.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-39948?
CVE-2023-39948 is a vulnerability in eprosima Fast DDS that can remotely crash any Fast DDS process prior to versions 2.10.0 and 2.6.5.
How severe is CVE-2023-39948?
CVE-2023-39948 has a severity rating of 7.5 (High).
Which software versions are affected by CVE-2023-39948?
CVE-2023-39948 affects eprosima Fast DDS versions prior to 2.10.0 and 2.6.5.
How can CVE-2023-39948 be exploited?
CVE-2023-39948 can be exploited remotely to crash any Fast DDS process.
How can I fix CVE-2023-39948?
To fix CVE-2023-39948, it is recommended to update to version 2.10.0 or 2.6.5 of eprosima Fast DDS.