FastDDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Prior to versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8, when a publisher serves a malformed `RTPS` packet, the subscriber crashes when creating `pthread`. This can remotely crash any Fast-DDS process, potentially leading to a DOS attack. Versions 2.14.1, 2.13.5, 2.10.4, and 2.6.8 contain a patch for the issue.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    27 Jan 2025, 18:19
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://drive.google.com/file/d/19W5UC52hPnAqVq_boZWO45d1TJ4WoCSh/view?usp=sharing - Exploit | |
| References | () https://github.com/eProsima/Fast-DDS/commit/65236f93e9c4ea3ff9a49fba4dfd9e43eb94037b - Patch | |
| References | () https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-53xw-465j-rxfh - Exploit, Vendor Advisory | |
| CWE | NVD-CWE-noinfo | |
| First Time | Eprosima fast Dds Eprosima | |
| CPE | cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:* cpe:2.3:a:eprosima:fast_dds:2.14.0:*:*:*:*:*:*:* | 
Information
                Published : 2024-05-14 15:22
Updated : 2025-01-27 18:19
NVD link : CVE-2024-30258
Mitre link : CVE-2024-30258
CVE.ORG link : CVE-2024-30258
JSON object : View
Products Affected
                eprosima
- fast_dds
CWE
                