Integer Underflow Vulnerability in Eclipse CycloneDDS by Eclipse Foundation
CVE-2024-10838
8.8HIGH
What is CVE-2024-10838?
This vulnerability arises from an integer underflow occurring during the deserialization process, enabling unauthenticated users to read out-of-bounds heap memory. This exposure can lead to the unauthenticated retrieval of sensitive data or pointers, potentially disclosing the layout of the address space within a deserialized data structure. Consequences may include thread crashes or triggering denial of service conditions, highlighting the critical need for timely patches and security measures.
Affected Version(s)
Eclipse Cyclone DDS 0 < 0.10.5