CVE-2024-26369: High severity eProsima FastDDS vulnerability
Published Mar 19, 2024
·Updated
An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data.
Affected Software
1 affected component
eProsima FastDDS>=2.6.x<2.12.x
Event History
Mar 19, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·06:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-26369?
CVE-2024-26369 has a high severity as it leads to a SIGABRT upon data reception in FastDDS.
2
How do I fix CVE-2024-26369?
To mitigate CVE-2024-26369, upgrade FastDDS to version 2.12.x, 2.11.x, or 2.10.x, as these versions contain a patch.
3
Which versions of FastDDS are affected by CVE-2024-26369?
CVE-2024-26369 affects FastDDS versions 2.6.x to 2.12.x.
4
What component is vulnerable in CVE-2024-26369?
The vulnerable component in CVE-2024-26369 is the HistoryQosPolicy in the FastDDS framework.
5
What type of issue does CVE-2024-26369 represent?
CVE-2024-26369 represents a critical issue that causes program termination due to a SIGABRT signal.