Debian Fastdds vulnerabilities
17 known vulnerabilities affecting debian/fastdds.
Total CVEs
17
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3HIGH12MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2021-38425P3HIGHCVSS 7.5fixed in fastdds 2.6.1+ds-1 (bookworm)2021
CVE-2021-38425 [HIGH] CVE-2021-38425: fastdds - eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitatio...
eProsima Fast DDS versions prior to 2.4.0 (#2269) are susceptible to exploitation when an attacker sends a specially crafted packet to flood a target device with unwanted traffic, which may result in a denial-of-service condition and information exposure.
Scope: local
bookworm: resolved (fixed in 2.6.1+ds-1)
bullseye: resolved (fixed in 2.1.0+ds-9+deb11u1)
forky: re
debian
CVE-2023-50716P3CRITICALCVSS 9.6fixed in fastdds 2.14.0+ds-2 (forky)2023
CVE-2023-50716 [CRITICAL] CVE-2023-50716: fastdds - eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distr...
eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7, an invalid DATA_FRAG Submessage causes a bad-free error, and the Fast-DDS process can be remotely terminated. If an invalid Data_Frag packet is sent, the `Inline_qos,
debian
CVE-2024-28231P3CRITICALCVSS 9.6fixed in fastdds 2.14.0+ds-2 (forky)2024
CVE-2024-28231 [CRITICAL] CVE-2024-28231: fastdds - eprosima Fast DDS is a C++ implementation of the Data Distribution Service stand...
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8, manipulated DATA Submessage can cause a heap overflow error in the Fast-DDS process, causing the process to be terminated remotely. Additionally, the payload_size in the DATA Submessage p
debian
CVE-2023-50257P3CRITICALCVSS 9.6fixed in fastdds 2.14.0+ds-2 (forky)2023
CVE-2023-50257 [CRITICAL] CVE-2023-50257: fastdds - eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distr...
eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Even with the application of SROS2, due to the issue where the data (`p[UD]`) and `guid` values used to disconnect between nodes are not encrypted, a vulnerability has been discovered where a malicious attacker can forcibly dis
debian
CVE-2024-30259P3HIGHCVSS 8.2fixed in fastdds 2.14.1+ds-1 (forky)2024
CVE-2024-30259 [HIGH] CVE-2024-30259: fastdds - FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard ...
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves malformed `RTPS` packet, heap buffer overflow occurs on the subscriber. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2
debian
CVE-2023-39946P3HIGHCVSS 8.2fixed in fastdds 2.9.1+ds-1+deb12u1 (bookworm)2023
CVE-2023-39946 [HIGH] CVE-2023-39946: fastdds - eprosima Fast DDS is a C++ implementation of the Data Distribution Service stand...
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, heap can be overflowed by providing a PID_PROPERTY_LIST parameter that contains a CDR string with length larger than the size of actual content. In `eprosima::fastdds::dds::ParameterPropertyList_t::pu
debian
CVE-2023-42459P3HIGHCVSS 8.6fixed in fastdds 2.9.1+ds-1+deb12u2 (bookworm)2023
CVE-2023-42459 [HIGH] CVE-2023-42459: fastdds - Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard...
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). In affected versions specific DATA submessages can be sent to a discovery locator which may trigger a free error. This can remotely crash any Fast-DDS process. The call to free() could potentially leave the pointer in the attackers control which cou
debian
CVE-2023-39945P3HIGHCVSS 8.2fixed in fastdds 2.9.1+ds-1+deb12u1 (bookworm)2023
CVE-2023-39945 [HIGH] CVE-2023-39945: fastdds - eprosima Fast DDS is a C++ implementation of the Data Distribution Service stand...
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5, a data submessage sent to PDP port raises unhandled `BadParamException` in fastcdr, which in turn crashes fastdds. Versions 2.11.0, 2.10.2, 2.9.2, and 2.6.5 contain a patch for this issue.
Scope: loca
debian
CVE-2024-30258P3HIGHCVSS 8.2fixed in fastdds 2.14.1+ds-1 (forky)2024
CVE-2024-30258 [HIGH] CVE-2024-30258: fastdds - FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard ...
FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves a malformed `RTPS` packet, the subscriber crashes when creating `pthread`. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1
debian
CVE-2024-26369P3HIGHCVSS 7.5fixed in fastdds 2.14.0+ds-2 (forky)2024
CVE-2024-26369 [HIGH] CVE-2024-26369: fastdds - An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x,...
An issue in the HistoryQosPolicy component of FastDDS v2.12.x, v2.11.x, v2.10.x, and v2.6.x leads to a SIGABRT (signal abort) upon receiving DataWriter's data.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.14.0+ds-2)
sid: resolved (fixed in 2.14.0+ds-2)
trixie: resolved (fixed in 2.14.0+ds-2)
debian
CVE-2023-39947P3HIGHCVSS 8.2fixed in fastdds 2.9.1+ds-1+deb12u1 (bookworm)2023
CVE-2023-39947 [HIGH] CVE-2023-39947: fastdds - eprosima Fast DDS is a C++ implementation of the Data Distribution Service stand...
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.11.1, 2.10.2, 2.9.2, and 2.6.6, even after the fix at commit 3492270, malformed `PID_PROPERTY_LIST` parameters cause heap overflow at a different program counter. This can remotely crash any Fast-DDS process. Versions 2.11.1, 2.10.2
debian
CVE-2023-39534P3HIGHCVSS 7.5fixed in fastdds 2.9.1+ds-1+deb12u1 (bookworm)2023
CVE-2023-39534 [HIGH] CVE-2023-39534: fastdds - eprosima Fast DDS is a C++ implementation of the Data Distribution Service stand...
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0, 2.9.2, and 2.6.5, a malformed GAP submessage can trigger assertion failure, crashing FastDDS. Version 2.10.0, 2.9.2, and 2.6.5 contain a patch for this issue.
Scope: local
bookworm: resolved (fixed in 2.9.1+ds-1+deb12u1)
bulls
debian
CVE-2023-39948P3HIGHCVSS 7.5fixed in fastdds 2.9.1+ds-1+deb12u1 (bookworm)2023
CVE-2023-39948 [HIGH] CVE-2023-39948: fastdds - eprosima Fast DDS is a C++ implementation of the Data Distribution Service stand...
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.10.0 and 2.6.5, the `BadParamException` thrown by Fast CDR is not caught in Fast DDS. This can remotely crash any Fast DDS process. Versions 2.10.0 and 2.6.5 contain a patch for this issue.
Scope: local
bookworm: resolved (fixed in
debian
CVE-2023-39949P3HIGHCVSS 7.5fixed in fastdds 2.9.1+ds-1+deb12u1 (bookworm)2023
CVE-2023-39949 [HIGH] CVE-2023-39949: fastdds - eprosima Fast DDS is a C++ implementation of the Data Distribution Service stand...
eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.9.1 and 2.6.5, improper validation of sequence numbers may lead to remotely reachable assertion failure. This can remotely crash any Fast-DDS process. Versions 2.9.1 and 2.6.5 contain a patch for this issue.
Scope: local
bookworm: r
debian
CVE-2025-24807P4MEDIUMCVSS 4.5fixed in fastdds 3.1.2+ds-1 (forky)2025
CVE-2025-24807 [MEDIUM] CVE-2025-24807: fastdds - eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service)...
eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.6.10, 2.10.7, 2.14.5, 3.0.2, 3.1.2, and 3.2.0, per design, PermissionsCA is not full chain validated, nor is the expiration date validated. Access control plugin validates only the S/MIME signature which causes an expi
debian
CVE-2024-30916P4HIGHCVSS 7.1fixed in fastdds 2.14.1+ds-1 (forky)2024
CVE-2024-30916 [HIGH] CVE-2024-30916: fastdds - An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local ...
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted max_samples parameter in DurabilityService QoS component.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.14.1+ds-1)
sid: resolved (fixed in 2.14.1+ds-1)
trixie: resolved (fi
debian
CVE-2024-30917P4MEDIUMCVSS 5.5fixed in fastdds 2.14.1+ds-1 (forky)2024
CVE-2024-30917 [MEDIUM] CVE-2024-30917: fastdds - An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local ...
An issue was discovered in eProsima FastDDS v.2.14.0 and before, allows a local attacker to cause a denial of service (DoS) and obtain sensitive information via a crafted history_depth parameter in DurabilityService QoS component.
Scope: local
bookworm: open
bullseye: open
forky: resolved (fixed in 2.14.1+ds-1)
sid: resolved (fixed in 2.14.1+ds-1)
trixie: resolved
debian