Memory Allocation Vulnerability in NASA's ION-DTN Product
CVE-2025-61910

7.5HIGH

Key Information:

Vendor

Nasa-jpl

Status
Vendor
CVE Published:
7 October 2025

What is CVE-2025-61910?

A vulnerability in NASA's Interplanetary Overlay Network (ION) product arises from improper handling of a malformed BPv7 bundle's extension block. This flaw can lead to uncontrolled memory allocation, resulting in termination of the receiver thread and a Denial-of-Service (DoS). Specifically, the bug occurs when a byte string in the extension block is processed incorrectly, causing excessive memory requests. The core issue relates to an improper unsigned to signed integer conversion that generates a massive allocation request, overwhelming system resources. Currently, there are no known patched versions to mitigate this vulnerability.

Affected Version(s)

ION-DTN = 4.1.3s

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-61910 : Memory Allocation Vulnerability in NASA's ION-DTN Product