{"id":"CVE-2026-75584","summary":"ION-DTN \u003c 4.2.1-a.1 Denial of Service via canonicalizePayloadBlock() Assertion","details":"ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsec_util.c passes bundle-\u003epayload.length to zco_clone() without validating it against zero, causing a failed CHKZERO assertion that triggers sm_Abort() and terminates the process with SIGABRT before any HMAC verification occurs, requiring no valid key or credential to exploit.","aliases":["GHSA-9vgc-2r6g-6qwf"],"modified":"2026-09-12T11:45:36.260620749Z","published":"2026-09-10T13:54:08.218Z","database_specific":{"cwe_ids":["CWE-617"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75584.json","cna_assigner":"VulnCheck"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/75xxx/CVE-2026-75584.json"},{"type":"ADVISORY","url":"https://github.com/nasa-jpl/ION-DTN/security/advisories/GHSA-9vgc-2r6g-6qwf"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-75584"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/ion-dtn-a-1-denial-of-service-via-canonicalizepayloadblock-assertion"},{"type":"PACKAGE","url":"https://github.com/nasa-jpl/ION-DTN"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/nasa-jpl/ion-dtn","events":[{"introduced":"0"},{"fixed":"4912bf82de7d03a9a11bf5d68614cc002f9ac911"}],"database_specific":{"extracted_events":[{"introduced":"0"},{"last_affected":"4.2.0"},{"fixed":"4.2.1-a.1"}],"source":["AFFECTED_FIELD","DESCRIPTION"]}}],"versions":["ion-open-source-4.2.0","ion-open-source-4.2.0-a.2","ion-open-source-4.2.0-a.1","ion-open-source-4.1.4","ion-open-source-4.1.4-b.2","ion-open-source-4.1.4-b.1","ion-open-source-4.1.4-a.2","ion-open-source-4.1.4-a.1","ion-open-source-4.1.3","ion-open-source-4.1.2","ion-open-source-4.1.1","ion-4.1.1-release","IOS-4.1.1","ion-3.6.0","ion-3.5.0","ion-3.4.0","ion-3.3.0","ion-3.2.0","ion-3.1.0","ion-3.0.0","ion-2.5.0","ion-2.4.0","ion-2.3.0","ion-2.2.1b","ion-2.2.1","ion-2.2.0","ion-2.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-75584.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}