CVE-2025-62600

NameCVE-2025-62600
DescriptionFast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes an Out-Of-Memory (OOM) condition, resulting in remote termination of Fast-DDS. If t he fields of PID_IDENTITY_TOKEN or PID_PERMISSION_TOKEN in the DATA Submessage — specifically by tampering with the length field in readBinaryPropertySeq — are modified, an integer overflow occurs, leading to an OOM during the resize operation. Versions 3.4.1, 3.3.1, and 2.6.11 patch the issue.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1121094

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
fastdds (PTS)bullseye (security), bullseye2.1.0+ds-9+deb11u1vulnerable
bookworm, bookworm (security)2.9.1+ds-1+deb12u2vulnerable
trixie3.1.2+ds-1vulnerable
forky, sid3.3.0+ds-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
fastddssource(unstable)(unfixed)1121094

Notes

[trixie] - fastdds <no-dsa> (Minor issue)
[bookworm] - fastdds <no-dsa> (Minor issue)
[bullseye] - fastdds <postponed> (Minor issue)
Fixed by: https://github.com/eProsima/Fast-DDS/commit/354218514d32beac963ff5c306f1cf159ee37c5f (v3.4.1)

Search for package or bug name: Reporting problems