CVE-2023-24010

NameCVE-2023-24010
DescriptionAn attacker can arbitrarily craft malicious DDS Participants (or ROS 2 Nodes) with valid certificates to compromise and get full control of the attacked secure DDS databus system by exploiting vulnerable attributes in the configuration of PKCS#7 certificate’s validation. This is caused by a non-compliant implementation of permission document verification used by some DDS vendors. Specifically, an improper use of the OpenSSL PKCS7_verify function used to validate S/MIME signatures.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1104239

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
fastdds (PTS)bullseye (security), bullseye2.1.0+ds-9+deb11u1vulnerable
bookworm, bookworm (security)2.9.1+ds-1+deb12u2vulnerable
trixie3.1.2+ds-1vulnerable
forky, sid3.3.0+ds-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
fastddssource(unstable)(unfixed)1104239

Notes

[trixie] - fastdds <no-dsa> (Minor issue)
[bookworm] - fastdds <no-dsa> (Minor issue)
https://github.com/ros2/sros2/issues/282

Search for package or bug name: Reporting problems