VulnerabilityAnalyzed
CVE-2024-10838
An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory.
HIGH 8.8EPSS 0.93%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.93%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead to thread crashes or cause denial of service conditions.
- CVSS 4.0
- 8.8 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.93% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-191
- Affected
- eclipse/cyclone data distribution service
- Source
- emo@eclipse.org
References
- https://github.com/eclipse-cyclonedds/cyclonedds/releases/tag/0.10.5Patch
- https://github.com/eclipse-cyclonedds/cyclonedds/security/advisories/GHSA-6jj6-w25p-jc42Exploit, Vendor Advisory
- https://gitlab.eclipse.org/security/cve-assignement/-/issues/46Issue Tracking, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.