{"id":"CVE-2024-28231","summary":"Manipulated DATA Submessage causes a heap-buffer-overflow error","details":"eprosima Fast DDS is a C++ implementation of the Data Distribution Service standard of the Object Management Group. Prior to versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8, manipulated DATA Submessage can cause a heap overflow error in the Fast-DDS process, causing the process to be terminated remotely. Additionally, the payload_size in the DATA Submessage packet is declared as uint32_t. When a negative number, such as -1, is input into this variable, it results in an Integer Overflow (for example, -1 gets converted to 0xFFFFFFFF). This eventually leads to a heap-buffer-overflow, causing the program to terminate. Versions 2.14.0, 2.13.4, 2.12.3, 2.10.4, and 2.6.8 contain a fix for this issue.","aliases":["GHSA-9m2j-qw67-ph4w"],"modified":"2026-09-14T08:12:55.281922Z","published":"2024-03-20T20:03:18.402Z","database_specific":{"cna_assigner":"GitHub_M","cwe_ids":["CWE-122"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28231.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/28xxx/CVE-2024-28231.json"},{"type":"ADVISORY","url":"https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-9m2j-qw67-ph4w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-28231"},{"type":"FIX","url":"https://github.com/eProsima/Fast-DDS/commit/355706386f4af9ce74125eeec3c449b06113112b"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eprosima/fast-dds","events":[{"introduced":"0"},{"fixed":"77cfbe8a3a831ac525dbaf4c741743f65f3316c1"},{"introduced":"eaeb0f593ad61fe77cf105c7ebbac44b60a13934"},{"fixed":"55b816d0551738384b0edaaef29ed86430c8e9bc"},{"introduced":"f633573e69e0552f5f0a48d5ed960a0782e2fea8"},{"fixed":"4c9252bd62d6761e13b63a6ef38d5c10b6a571c6"},{"fixed":"355706386f4af9ce74125eeec3c449b06113112b"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"fixed":"2.6.8"},{"introduced":"2.7.0"},{"fixed":"2.10.4"},{"introduced":"2.13.0"},{"fixed":"2.13.4"}],"source":["CPE_RANGE","REFERENCES"],"cpe":"cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*"}}],"versions":["v2.10.1-rc1","v2.10.0-rc1","v2.3.0-1","v2.3.0-api","v2.2.0","v2.1.0","2.0.0-rc","2.0.0-beta","v1.7.2","Discovery-Time_Data_Typing","v1.9.0","v1.9.0-beta-2","v1.9.0-beta","v1.8.0-2","v1.8.0","v1.7.1","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-28231.json","vanir_signatures_modified":"2026-09-14T08:12:55Z","vanir_signatures":[{"digest":{"function_hash":"324427933685653720667523570866654147901","length":6264},"id":"CVE-2024-28231-00602aa5","signature_type":"Function","signature_version":"v1","source":"https://github.com/eprosima/fast-dds/commit/55b816d0551738384b0edaaef29ed86430c8e9bc","target":{"file":"src/cpp/rtps/participant/RTPSParticipantImpl.cpp","function":"RTPSParticipantImpl::update_attributes"},"deprecated":false},{"target":{"file":"src/cpp/rtps/messages/MessageReceiver.cpp","function":"MessageReceiver::proc_Submsg_Data"},"deprecated":false,"digest":{"function_hash":"57756825430100399171828094915205380164","length":4056},"id":"CVE-2024-28231-029973bd","signature_type":"Function","signature_version":"v1","source":"https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b"},{"id":"CVE-2024-28231-63fc6a40","signature_type":"Line","signature_version":"v1","source":"https://github.com/eprosima/fast-dds/commit/55b816d0551738384b0edaaef29ed86430c8e9bc","target":{"file":"src/cpp/rtps/participant/RTPSParticipantImpl.cpp"},"deprecated":false,"digest":{"line_hashes":["262956306831166481237303932868870361372","306604317174497932475465898607727697833","196513365605387483283372719964676140728","294552922959227129118208678759959282933","233002817893507405036982977419080917531","137118083659526854717517586406070424281"],"threshold":0.9}},{"target":{"file":"test/blackbox/common/BlackboxTestsSecurity.cpp"},"deprecated":false,"digest":{"line_hashes":["228362837859764186937628672634867461790","260462637404707715072414127588979219351","298297286387321257859828901400011176313","80611033387595130394937903734311482349","151752262408554203708411395488155196554","62201320530053988169619986810667123393","257913551245389387412636012826639459012","7295173455095510914387581127920113975","129276899805442969717290919219209459589","146897607664667051136985427779409031399","196638631524338650019825150580400122667","170981034697217389057390813593059476814","319917395306065682145937709193660548275","128402701207872786042366067012169513179","7760413694028855983966765921493268116","338439588685906172735552277455786899158","10457817176578273930685764084181603213","34469216426985706484583985536182314257","111033157590873430370058866427320370869","285349723214172981170000098779696881390","174030565935855499138904716612754336153","195585147046584551504275222814334696737","122130876898372960923339143454616388161","108664835625197678255852206923456349157","213069196146339316052572187303433355","121086408290602251121013642200146354411","156949058853479151704679985163819369339","235914956100815664529914860892879882646"],"threshold":0.9},"id":"CVE-2024-28231-99fb5d68","signature_type":"Line","signature_version":"v1","source":"https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b"},{"source":"https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b","target":{"file":"src/cpp/rtps/messages/MessageReceiver.cpp"},"deprecated":false,"digest":{"line_hashes":["289308615572724561719612065558834103599","17079969515649584130394596763697447978","234930100058169986525429270354391827092","304249472030726670955389077814598410866","4160453209353187470367252711424999338"],"threshold":0.9},"id":"CVE-2024-28231-aba99743","signature_type":"Line","signature_version":"v1"},{"digest":{"threshold":0.9,"line_hashes":["172351372739125121081423145525075712226","246414798708922273302520668842721479960","173741567523793428809287956416152861434","72523864604251325746317380080504029323","148219779269303719870637007832585220127","210082573897439651162728501548290189520","113681397175657157165245792835402023352","225694970296841836573442565655444194076","273539768536017587225882120492261047024","305812903942293525020306963851390566032","128976218983297145883485366634531103692","145814424165313990436493598265336584509","35423151694348500894838074309184101211"]},"id":"CVE-2024-28231-c862352c","signature_type":"Line","signature_version":"v1","source":"https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b","target":{"file":"test/blackbox/common/BlackboxTests.hpp"},"deprecated":false},{"id":"CVE-2024-28231-cf3e9ecd","signature_type":"Line","signature_version":"v1","source":"https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b","target":{"file":"test/blackbox/common/BlackboxTestsTransportUDP.cpp"},"deprecated":false,"digest":{"line_hashes":["273428657871749477938630944099209761282","92696485777743894906031357355284279012","266836595062577252441759963205913252192","154323065948988608906864646909510266771","1734961587240811426265729414747424103","133074155187995029782159754498984886070","98437061592372373352639911106583611558"],"threshold":0.9}},{"digest":{"line_hashes":["169262875442188660459318678217996232359","17041737833915821215457832314843480551","151877993733996997753152245506746350239","256814751757310043197895025514332701785","227797968036593524780055328510809145088","171009758921934833923271354610273660467","287374787052714152624697871427648250886","262716262916870967099047554430688757710","54550304990772621898226917116677701228","81146058010836822764991687495864066969","155019943999758250493335899026300300442"],"threshold":0.9},"id":"CVE-2024-28231-f77858c9","signature_type":"Line","signature_version":"v1","source":"https://github.com/eprosima/fast-dds/commit/355706386f4af9ce74125eeec3c449b06113112b","target":{"file":"test/blackbox/api/fastrtps_deprecated/PubSubReader.hpp"},"deprecated":false}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}