Denial of Service Vulnerability in ION-DTN by NASA
CVE-2026-75584

8.7HIGH

Key Information:

Vendor

Nasa-jpl

Status
Vendor
CVE Published:
10 September 2026

What is CVE-2026-75584?

ION-DTN prior to version 4.2.1-a.1 is susceptible to a denial of service attack which can be executed by unauthenticated remote attackers. By dispatching a BPv7 bundle with a zero-length payload, an attacker can trigger a failure in the canonicalizePayloadBlock() function. This leads to the zco_clone() method receiving an unchecked payload length, resulting in a failed assertion and subsequent process termination through SIGABRT, effectively crashing the ION process before any crucial HMAC verification can take place, requiring no valid authentication for exploitation.

Affected Version(s)

ION-DTN 0 <= 4.2.0

ION-DTN 4.2.1-a.1

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Asadbek Fatullayev
VulnCheck
.