Impact
A recursion error in Fast DDS’s DDSSQLFilter causes a stack exhaustion when parsing a deeply nested filter expression supplied in a SEDP DATA submessage. An attacker who can send such a message to a DDS domain participant can force that participant to crash, terminating its service without gaining code execution or compromising data confidentiality. The flaw is strictly a denial‑of‑service vulnerability.
Affected Systems
eProsima Fast‑DDS releases prior to 2.6.12, 2.14.6, 3.2.4, and 3.4.3 are vulnerable. Any participant running one of these versions in a DDS domain is affected. All newer releases contain the fix.
Risk and Exploitability
The CVSS score of 7.5 indicates a high severity DoS risk. EPSS information is unavailable, but the vulnerability can be triggered remotely by any participant that can craft a SEDP DATA submessage with a malicious filter. Although KEV does not list this entry, the remote attack surface and potential for distributed denial of service warrant close monitoring. The flaw requires only message construction and network transmission; no local privilege escalation is needed.
OpenCVE Enrichment