CVE-2023-52427: High severity eclipse vulnerability
In OpenDDS through 3.27, there is a segmentation fault for a DataWriter with a large value of resourcelimits.maxsamples. NOTE: the vendor's position is that the product is not designed to handle a maxsamples value that is too large for the amount of memory on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52427?
CVE-2023-52427 has a high severity due to the potential for a segmentation fault in the OpenDDS software.
How do I fix CVE-2023-52427?
To mitigate CVE-2023-52427, ensure that the resource_limits.max_samples value is set appropriately to avoid exceeding system memory limits.
Which versions of OpenDDS are affected by CVE-2023-52427?
CVE-2023-52427 affects OpenDDS versions up to and including 3.27.
What are the consequences of CVE-2023-52427?
The consequence of CVE-2023-52427 is a segmentation fault that can lead to application crashes.
Is there a workaround for CVE-2023-52427?
Yes, you can work around CVE-2023-52427 by configuring a lower max_samples value within the resource limits.