CVE-2024-54130: Segmentation Fault in `forwardBundle` Function of ION-DTN BPv7 When Destination EID is `dtn:none` (public)
The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A segmentation fault occurs with ION-DTN BPv7 software version 4.1.3 when a bundle with a Destination Endpoint ID (EID) set to dtn:none is received. This causes the node to become unresponsive to incoming bundles, leading to a Denial of Service (DoS) condition. This vulnerability is fixed in 4.1.3s.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-54130?
The severity of CVE-2024-54130 is classified as high due to the potential for Denial of Service caused by a segmentation fault.
How do I fix CVE-2024-54130?
To fix CVE-2024-54130, upgrade the NASA ION-DTN BPv7 software to version 4.1.3s or later.
What does CVE-2024-54130 affect?
CVE-2024-54130 affects the NASA ION-DTN BPv7 software specifically version 4.1.3 and earlier.
What type of vulnerability is CVE-2024-54130?
CVE-2024-54130 is a vulnerability that results in a segmentation fault leading to potential Denial of Service.
What causes CVE-2024-54130?
CVE-2024-54130 is caused by the reception of a bundle with a Destination Endpoint ID set to dtn:none in the ION-DTN BPv7 software.