Denial of Service Vulnerability in ION-DTN by NASA
CVE-2026-75584
8.7HIGH
What is CVE-2026-75584?
ION-DTN prior to version 4.2.1-a.1 is susceptible to a denial of service attack which can be executed by unauthenticated remote attackers. By dispatching a BPv7 bundle with a zero-length payload, an attacker can trigger a failure in the canonicalizePayloadBlock() function. This leads to the zco_clone() method receiving an unchecked payload length, resulting in a failed assertion and subsequent process termination through SIGABRT, effectively crashing the ION process before any crucial HMAC verification can take place, requiring no valid authentication for exploitation.
Affected Version(s)
ION-DTN 0 <= 4.2.0
ION-DTN 4.2.1-a.1
