CVE-2025-62600: eprosima Fast DDS affected by Out-of-Memory in readBinaryPropertySeq via Manipulated DATA Submessage when DDS Security is enabled
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to 2.6.11, 2.14.6, 3.2.4, 3.3.1, and 3.4.1, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OOM) condition, resulting in remote termination of Fast-DDS. If the fields of PIDIDENTITYTOKEN or PIDPERMISSIONTOKEN in the DATA Submessage — specifically by tampering with the length field in readBinaryPropertySeq— are modified, an integer overflow occurs, leading to an OOM during the resize operation. This vulnerability is fixed in 2.6.11, 2.14.6, 3.2.4, 3.3.1, and 3.4.1.
Other sources
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OOM) condition, resulting in remote termination of Fast-DDS. If t he fields of PIDIDENTITYTOKEN or PIDPERMISSIONTOKEN in the DATA Submessage — specifically by tampering with the length field in readBinaryPropertySeq — are modified, an integer overflow occurs, leading to an OOM during the resize operation. Versions 3.4.1, 3.3.1, and 2.6.11 patch the issue.
— Debian
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-62600?
CVE-2025-62600 is considered a critical vulnerability due to the Out-of-Memory issue that can potentially lead to application crashes.
How do I fix CVE-2025-62600?
To fix CVE-2025-62600, upgrade to versions 2.6.11, 3.3.1 or 3.4.1 of eProsima Fast DDS, ensuring that you have the latest security patches applied.
What software is affected by CVE-2025-62600?
CVE-2025-62600 affects eProsima Fast DDS versions prior to 2.6.11, 3.3.1, and 3.4.1, as well as certain Debian packages of fastdds.
Is CVE-2025-62600 exploitable remotely?
Yes, CVE-2025-62600 could be exploited remotely when DDS Security is enabled, making it a significant risk in networked environments.
What are the implications of CVE-2025-62600 for systems using Fast DDS?
The implications include potential application instability and denial of service, which can critically impact systems relying on Fast DDS for data distribution.