CVE-2024-28231

Source
https://cve.org/CVERecord?id=CVE-2024-28231
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28231.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2024-28231
Aliases
  • GHSA-9m2j-qw67-ph4w
Downstream
Published
2024-03-20T20:03:18.402Z
Modified
2026-07-22T00:45:47.227546Z
Severity
  • 9.6 (Critical) CVSS_V3 - CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Manipulated DATA Submessage causes a heap-buffer-overflow error
Details

eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8, manipulated DATA Submessage can cause a heap overflow error in the Fast-DDS process, causing the process to be terminated remotely. Additionally, the payloadsize in the DATA Submessage packet is declared as uint32t. When a negative number, such as -1, is input into this variable, it results in an Integer Overflow (for example, -1 gets converted to 0xFFFFFFFF). This eventually leads to a heap-buffer-overflow, causing the program to terminate. Versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8 contain a fix for this issue.

Database specific
{
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28231.json",
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-122"
    ]
}
References

Affected packages

Git / github.com/eprosima/fast-dds

Affected ranges

Type
GIT
Repo
https://github.com/eprosima/fast-dds
Events
Database specific
{
    "source": [
        "CPE_RANGE",
        "REFERENCES"
    ],
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2.6.8"
        },
        {
            "introduced": "2.7.0"
        },
        {
            "fixed": "2.10.4"
        },
        {
            "introduced": "2.13.0"
        },
        {
            "fixed": "2.13.4"
        }
    ],
    "cpe": "cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*"
}

Affected versions

2.*
2.0.0-beta
2.0.0-rc
Other
Discovery-Time_Data_Typing
v1.*
v1.0.0
v1.3.0
v1.4.0
v1.5.0
v1.6.0
v1.7.0
v1.7.1
v1.7.2
v1.8.0
v1.8.0-2
v1.9.0
v1.9.0-beta
v1.9.0-beta-2
v2.*
v2.1.0
v2.10.0-rc1
v2.10.1-rc1
v2.10.4
v2.2.0
v2.3.0-1
v2.3.0-api

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28231.json"
vanir_signatures_modified
"2026-07-22T00:45:47Z"
vanir_signatures
[
    {
        "target": {
            "file": "src/cpp/rtps/messages/MessageReceiver.cpp",
            "function": "MessageReceiver::proc_Submsg_Data"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2024-28231-029973bd",
        "signature_version": "v1",
        "source": "https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b",
        "digest": {
            "function_hash": "57756825430100399171828094915205380164",
            "length": 4056.0
        }
    },
    {
        "target": {
            "file": "src/cpp/rtps/participant/RTPSParticipantImpl.cpp"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2024-28231-725a5a7b",
        "signature_version": "v1",
        "source": "https://github.com/eprosima/fast-dds/commit/3118cba80c7b0db2c9bd0ede8671e3d31785cbda",
        "digest": {
            "line_hashes": [
                "262956306831166481237303932868870361372",
                "306604317174497932475465898607727697833",
                "196513365605387483283372719964676140728",
                "294552922959227129118208678759959282933",
                "233002817893507405036982977419080917531",
                "137118083659526854717517586406070424281"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "test/blackbox/common/BlackboxTestsSecurity.cpp"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2024-28231-99fb5d68",
        "signature_version": "v1",
        "source": "https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b",
        "digest": {
            "line_hashes": [
                "228362837859764186937628672634867461790",
                "260462637404707715072414127588979219351",
                "298297286387321257859828901400011176313",
                "80611033387595130394937903734311482349",
                "151752262408554203708411395488155196554",
                "62201320530053988169619986810667123393",
                "257913551245389387412636012826639459012",
                "7295173455095510914387581127920113975",
                "129276899805442969717290919219209459589",
                "146897607664667051136985427779409031399",
                "196638631524338650019825150580400122667",
                "170981034697217389057390813593059476814",
                "319917395306065682145937709193660548275",
                "128402701207872786042366067012169513179",
                "7760413694028855983966765921493268116",
                "338439588685906172735552277455786899158",
                "10457817176578273930685764084181603213",
                "34469216426985706484583985536182314257",
                "111033157590873430370058866427320370869",
                "285349723214172981170000098779696881390",
                "174030565935855499138904716612754336153",
                "195585147046584551504275222814334696737",
                "122130876898372960923339143454616388161",
                "108664835625197678255852206923456349157",
                "213069196146339316052572187303433355",
                "121086408290602251121013642200146354411",
                "156949058853479151704679985163819369339",
                "235914956100815664529914860892879882646"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "src/cpp/rtps/messages/MessageReceiver.cpp"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2024-28231-aba99743",
        "signature_version": "v1",
        "source": "https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b",
        "digest": {
            "line_hashes": [
                "289308615572724561719612065558834103599",
                "17079969515649584130394596763697447978",
                "234930100058169986525429270354391827092",
                "304249472030726670955389077814598410866",
                "4160453209353187470367252711424999338"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "test/blackbox/common/BlackboxTests.hpp"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2024-28231-c862352c",
        "signature_version": "v1",
        "source": "https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b",
        "digest": {
            "line_hashes": [
                "172351372739125121081423145525075712226",
                "246414798708922273302520668842721479960",
                "173741567523793428809287956416152861434",
                "72523864604251325746317380080504029323",
                "148219779269303719870637007832585220127",
                "210082573897439651162728501548290189520",
                "113681397175657157165245792835402023352",
                "225694970296841836573442565655444194076",
                "273539768536017587225882120492261047024",
                "305812903942293525020306963851390566032",
                "128976218983297145883485366634531103692",
                "145814424165313990436493598265336584509",
                "35423151694348500894838074309184101211"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "test/blackbox/common/BlackboxTestsTransportUDP.cpp"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2024-28231-cf3e9ecd",
        "signature_version": "v1",
        "source": "https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b",
        "digest": {
            "line_hashes": [
                "273428657871749477938630944099209761282",
                "92696485777743894906031357355284279012",
                "266836595062577252441759963205913252192",
                "154323065948988608906864646909510266771",
                "1734961587240811426265729414747424103",
                "133074155187995029782159754498984886070",
                "98437061592372373352639911106583611558"
            ],
            "threshold": 0.9
        }
    },
    {
        "target": {
            "file": "src/cpp/rtps/participant/RTPSParticipantImpl.cpp",
            "function": "RTPSParticipantImpl::update_attributes"
        },
        "deprecated": false,
        "signature_type": "Function",
        "id": "CVE-2024-28231-ecb73c2a",
        "signature_version": "v1",
        "source": "https://github.com/eprosima/fast-dds/commit/3118cba80c7b0db2c9bd0ede8671e3d31785cbda",
        "digest": {
            "function_hash": "324427933685653720667523570866654147901",
            "length": 6264.0
        }
    },
    {
        "target": {
            "file": "test/blackbox/api/fastrtps_deprecated/PubSubReader.hpp"
        },
        "deprecated": false,
        "signature_type": "Line",
        "id": "CVE-2024-28231-f77858c9",
        "signature_version": "v1",
        "source": "https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b",
        "digest": {
            "line_hashes": [
                "169262875442188660459318678217996232359",
                "17041737833915821215457832314843480551",
                "151877993733996997753152245506746350239",
                "256814751757310043197895025514332701785",
                "227797968036593524780055328510809145088",
                "171009758921934833923271354610273660467",
                "287374787052714152624697871427648250886",
                "262716262916870967099047554430688757710",
                "54550304990772621898226917116677701228",
                "81146058010836822764991687495864066969",
                "155019943999758250493335899026300300442"
            ],
            "threshold": 0.9
        }
    }
]