Memory Allocation Vulnerability in NASA's ION-DTN Product
CVE-2025-61910
7.5HIGH
What is CVE-2025-61910?
A vulnerability in NASA's Interplanetary Overlay Network (ION) product arises from improper handling of a malformed BPv7 bundle's extension block. This flaw can lead to uncontrolled memory allocation, resulting in termination of the receiver thread and a Denial-of-Service (DoS). Specifically, the bug occurs when a byte string in the extension block is processed incorrectly, causing excessive memory requests. The core issue relates to an improper unsigned to signed integer conversion that generates a massive allocation request, overwhelming system resources. Currently, there are no known patched versions to mitigate this vulnerability.
Affected Version(s)
ION-DTN = 4.1.3s