Memory Management Flaw in Fast DDS Product by eProsima
CVE-2025-62603

1.7LOW

Key Information:

Vendor

Eprosima

Status
Vendor
CVE Published:
3 February 2026

What is CVE-2025-62603?

Fast DDS, a C++ implementation of DDS, faces a vulnerability in its handling of security control messages, specifically the deserialization of the DataHolderSeq. The flawed parsing method fails to conduct essential structural checks, which can lead to excessive memory usage, resulting in an out-of-memory condition. This scenario can ultimately lead to an unexpected termination of the process. The issue is particularly prevalent in versions prior to 3.4.1, 3.3.1, and 2.6.11, where the complete parsing of the DataHolderSeq occurs without minimal header checks, thus exposing systems to potential disruptions. Subsequent versions have addressed this flaw, reinforcing the importance of updating to the latest available versions for enhanced security.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Fast-DDS 3.4.0 < 3.4.1

Fast-DDS 3.0.0 < 3.3.1

Fast-DDS 0 < 2.6.11

References

CVSS V4

Score:
1.7
Severity:
LOW
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.