CVE-2023-39949
Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.04%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 1.04% probability · 62th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-617
- Affected
- eprosima/fast dds · debian/debian linux
- Source
- security-advisories@github.com
References
- https://github.com/eProsima/Fast-DDS/blob/v2.9.0/src/cpp/rtps/messages/MessageReceiver.cpp#L1059Third Party Advisory
- https://github.com/eProsima/Fast-DDS/issues/3236Third Party Advisory
- https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-3jv9-j9x3-95cgThird Party Advisory
- https://www.debian.org/security/2023/dsa-5481Third Party Advisory
- https://github.com/eProsima/Fast-DDS/blob/v2.9.0/src/cpp/rtps/messages/MessageReceiver.cpp#L1059Third Party Advisory
- https://github.com/eProsima/Fast-DDS/issues/3236Third Party Advisory
- https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-3jv9-j9x3-95cgThird Party Advisory
- https://www.debian.org/security/2023/dsa-5481Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.