Memory Management Flaw in Fast DDS Product by eProsima
CVE-2025-62603
What is CVE-2025-62603?
Fast DDS, a C++ implementation of DDS, faces a vulnerability in its handling of security control messages, specifically the deserialization of the DataHolderSeq. The flawed parsing method fails to conduct essential structural checks, which can lead to excessive memory usage, resulting in an out-of-memory condition. This scenario can ultimately lead to an unexpected termination of the process. The issue is particularly prevalent in versions prior to 3.4.1, 3.3.1, and 2.6.11, where the complete parsing of the DataHolderSeq occurs without minimal header checks, thus exposing systems to potential disruptions. Subsequent versions have addressed this flaw, reinforcing the importance of updating to the latest available versions for enhanced security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fast-DDS 3.4.0 < 3.4.1
Fast-DDS 3.0.0 < 3.3.1
Fast-DDS 0 < 2.6.11
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
