{"id":"CVE-2023-50716","summary":"Invalid DATA_FRAG Submessage causes a bad-free error","details":"eProsima Fast DDS (formerly Fast RTPS) is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.13.0, 2.12.2, 2.11.3, 2.10.3, and 2.6.7, an invalid DATA_FRAG Submessage causes a bad-free error, and the Fast-DDS process can be remotely terminated. If an invalid Data_Frag packet is sent, the `Inline_qos, SerializedPayload` member of object `ch` will attempt to release memory without initialization, resulting in a 'bad-free' error. Versions 2.13.0, 2.12.2, 2.11.3, 2.10.2, and 2.6.7 fix this issue.","aliases":["GHSA-5m2f-hvj2-cx2h"],"modified":"2026-08-12T03:51:26.150805482Z","published":"2024-03-06T17:23:55.916Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-416"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50716.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/50xxx/CVE-2023-50716.json"},{"type":"ADVISORY","url":"https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-5m2f-hvj2-cx2h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-50716"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eprosima/fast-dds","events":[{"introduced":"0"},{"fixed":"125f90341a52d73abcfa5621f9bb51895cf44bbb"},{"introduced":"463d59ca81c7fd732edf45b982a58c0b54fc1da4"},{"fixed":"5ac1dbacc7847f9bc080328930a7a8adcada2fe5"},{"introduced":"64700fcb9058c14e3c7aeee0ec130c47c9824917"},{"fixed":"13ccafc09fe95873fa22d2bd13e3a331efb6a01c"},{"introduced":"9489d2056015c89cee1d93d8e8453d997ffecf33"},{"fixed":"092848725b8425e4f05a8ccf7b3b8d513fabf733"}],"database_specific":{"source":"CPE_RANGE","cpe":"cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"fixed":"2.6.7"},{"introduced":"2.10.0"},{"fixed":"2.10.3"},{"introduced":"2.11.0"},{"fixed":"2.11.3"},{"introduced":"2.12.0"},{"fixed":"2.12.2"}]}}],"versions":["v2.10.1-rc1","v2.10.0-rc1","v2.3.0-1","v2.3.0-api","v2.2.0","v2.1.0","2.0.0-rc","2.0.0-beta","v1.7.2","Discovery-Time_Data_Typing","v1.9.0","v1.9.0-beta-2","v1.9.0-beta","v1.8.0-2","v1.8.0","v1.7.1","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-50716.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}