CVE-2025-62599: eprosima Fast DDS affected by Out-of-Memory in readPropertySeq via Manipulated DATA Submessage when DDS Security is enabled
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to 2.6.11, 2.14.6, 3.2.4, 3.3.1, and 3.4.1, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OOM) condition, resulting in remote termination of Fast-DDS. If the fields of PIDIDENTITYTOKEN or PIDPERMISSIONTOKEN in the DATA Submessage — specifically by tampering with the length field in readPropertySeq — are modified, an integer overflow occurs, leading to an OOM during the resize operation. This vulnerability is fixed in 2.6.11, 2.14.6, 3.2.4, 3.3.1, and 3.4.1.
Other sources
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OOM) condition, resulting in remote termination of Fast-DDS. If t he fields of PIDIDENTITYTOKEN or PIDPERMISSIONTOKEN in the DATA Submessage — specifically by tampering with the length field in readPropertySeq — are modified, an integer overflow occurs, leading to an OOM during the resize operation. Versi ons 3.4.1, 3.3.1, and 2.6.11 patch the issue.
— Debian
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62599?
CVE-2025-62599 is considered a critical vulnerability due to the potential for an Out-of-Memory condition when using FastDDS with DDS Security enabled.
How do I fix CVE-2025-62599?
To fix CVE-2025-62599, upgrade to FastDDS versions 3.4.1, 3.3.1, or 2.6.11 or later.
What versions of FastDDS are affected by CVE-2025-62599?
Versions of FastDDS prior to 3.4.1, 3.3.1, and 2.6.11 are affected by CVE-2025-62599.
What is the impact of CVE-2025-62599 on systems using FastDDS?
CVE-2025-62599 can lead to an Out-of-Memory error, potentially disrupting the operation of applications using FastDDS.
Is there a workaround for CVE-2025-62599?
There is no specific workaround for CVE-2025-62599; upgrading to a patched version is recommended.