{"id":"CVE-2026-22590","summary":"Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG  sampleSize / fragmentsInSubmessage","details":"eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read while processing RTPS `DATA_FRAG` submessages. An attacker can craft a `DATA_FRAG` with a large `sampleSize` but a small actual payload, and set `fragmentsInSubmessage` such that the receiver treats the packet as the LAST fragment**. In this LAST-fragment path, Fast-DDS computes `incoming_length` based on `sampleSize` and calls `memcpy()` without validating `incoming_data.length \u003e= incoming_length`. As a result, `CacheChange_t::add_fragments()` reads past the received UDP datagram buffer and into adjacent heap memory, copying those bytes into the reassembly buffer. In a Discovery Server deployment, the resulting `CacheChange_t` can be relayed to other participants, meaning that a newly joining participant may receive leaked heap memory (e.g., pointer values that could aid ASLR bypass). Versions 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 fix the issue.","aliases":["GHSA-7r7h-hwfj-q626"],"modified":"2026-09-11T03:31:02.450134774Z","published":"2026-09-09T15:43:28.589Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22590.json","cna_assigner":"GitHub_M","cwe_ids":["CWE-125","CWE-131"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/22xxx/CVE-2026-22590.json"},{"type":"ADVISORY","url":"https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-7r7h-hwfj-q626"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-22590"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eprosima/fast-dds","events":[{"introduced":"0"},{"fixed":"ac5c7b9014cd5b2bebf9c4b04dc229ca5a0a4338"},{"introduced":"eaeb0f593ad61fe77cf105c7ebbac44b60a13934"},{"fixed":"f052f239538ebc0df56835fdb57f7628628010bc"},{"introduced":"c53cd0a425e6f5483fbd971eb584b4360c306891"},{"fixed":"942570bf1f90701bba0c1e3bbca82569c1e966c2"},{"introduced":"94940169442298e2736af79720ef05d89a1b2a7d"},{"fixed":"4ba5a3b754ee4fd40f8ae0feb3aff7e6708aae4a"},{"introduced":"bf1d4c34c3b2b6267cd854346b1477854967264e"},{"fixed":"3d24aeecbb9bb5b4fc477904c44e032d6311e6d3"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"fixed":"2.6.12"},{"introduced":"2.7.0"},{"fixed":"2.14.6"},{"introduced":"3.0.0"},{"fixed":"3.2.4"},{"introduced":"3.3.0"},{"fixed":"3.3.1"},{"introduced":"3.4.0"},{"fixed":"3.4.2"}]}}],"versions":["v2.10.1-rc1","v2.10.0-rc1","v2.3.0-1","v2.3.0-api","v2.2.0","v2.1.0","2.0.0-rc","2.0.0-beta","v1.7.2","Discovery-Time_Data_Typing","v1.9.0","v1.9.0-beta-2","v1.9.0-beta","v1.8.0-2","v1.8.0","v1.7.1","v1.7.0","v1.6.0","v1.5.0","v1.4.0","v1.3.0","v1.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-22590.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H"}]}