eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7, an invalid DATA_FRAG Submessage causes a bad-free error, and the Fast-DDS process can be remotely terminated. If an invalid Data_Frag packet is sent, the `Inline_qos, SerializedPayload` member of object `ch` will attempt to release memory without initialization, resulting in a 'bad-free' error. Versions 2.13.0, 2.12.2, 2.11.3, 2.10.2, and 2.6.7 fix this issue.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-55487 eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7, an invalid DATA_FRAG Submessage causes a bad-free error, and the Fast-DDS process can be remotely terminated. If an invalid Data_Frag packet is sent, the `Inline_qos, SerializedPayload` member of object `ch` will attempt to release memory without initialization, resulting in a 'bad-free' error. Versions 2.13.0, 2.12.2, 2.11.3, 2.10.2, and 2.6.7 fix this issue.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 16 Apr 2025 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Eprosima
Eprosima fast Dds
CPEs cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*
Vendors & Products Eprosima
Eprosima fast Dds

cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2024-08-02T22:16:47.221Z

Reserved: 2023-12-11T17:53:36.029Z

Link: CVE-2023-50716

cve-icon Vulnrichment

Updated: 2024-08-02T22:16:47.221Z

cve-icon NVD

Status : Analyzed

Published: 2024-03-06T18:15:46.360

Modified: 2025-04-16T16:21:22.597

Link: CVE-2023-50716

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.