Description
ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.
Published: 2026-09-02
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability occurs in the decodeSdnv function of ION-DTN versions before 4.2.0. Unauthenticated remote attackers can send a truncated SDNV in a UDP datagram to the LTP link service input port. The function then performs an out-of-bounds read that can retrieve up to nine bytes beyond the intended buffer, enabling the attacker to read arbitrary memory contents. A memory disclosure can lead to sensitive data leakage or aid further attacks.

Affected Systems

The affected product is NASA JPL’s ION‑DTN software, available before release 4.2.0. Any deployment running versions such as 4.1.x or earlier is vulnerable. The vulnerability resides within the core library used by the LTP link service.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. No EPSS data is available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. Attackers can exploit the flaw remotely by sending a malicious UDP packet; the flaw does not require privileges or authentication, making it readily actionable in uncontrolled networks.

Generated by OpenCVE AI on September 2, 2026 at 03:52 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update ION‑DTN to version 4.2.0 or later as released by NASA JPL.
  • Restart the ION‑DTN services to apply the new binaries.
  • As a temporary measure, restrict UDP traffic to the LTP link service input port from untrusted sources until the upgrade is deployed.

Generated by OpenCVE AI on September 2, 2026 at 03:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 02 Sep 2026 01:45:00 +0000

Type Values Removed Values Added
Description ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.
Title ION-DTN before 4.2.0 Out-of-Bounds Read via decodeSdnv
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-02T01:18:14.970Z

Reserved: 2026-09-01T20:37:00.841Z

Link: CVE-2026-84484

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-02T02:17:20.450

Modified: 2026-09-02T02:17:20.450

Link: CVE-2026-84484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-02T04:00:09Z

Weaknesses