← Back to CVE List
Vulnerability Intelligence Report
Fast-DDS Discovery Server: Out-of-Bounds Read & Heap Memory Disclosure via DATA_FRAG  sampleSize / fragmentsInSubmessage

CVE-2026-22590

eprosima Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). Versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 have a remotely triggerable Out-of-Bounds Read while processing RTPS `DATA_FRAG` submessages. An attacker can craft a `DATA_FRAG` with a large `sampleSize` but a small actual payload, and set `fragmentsInSubmessage` such that the receiver treats the packet as the LAST fragment**. In this LAST-fragment path, Fast-DDS computes `incoming_length` based on `sampleSize` and calls `memcpy()` without validating `incoming_data.length >= incoming_length`. As a result, `CacheChange_t::add_fragments()` reads past the received UDP datagram buffer and into adjacent heap memory, copying those bytes into the reassembly buffer. In a Discovery Server deployment, the resulting `CacheChange_t` can be relayed to other participants, meaning that a newly joining participant may receive leaked heap memory (e.g., pointer values that could aid ASLR bypass). Versions 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2 fix the issue.

No Active Exploit Signals
CVSS Base Score
9.1
CRITICAL
Exploitability:3.9
Impact Score:5.2
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-125 ↗CWE-125: Out-of-bounds Read
CWE-131 ↗CWE-131: Incorrect Calculation of Buffer Size

Affected Products & Versions

Vendor Product Affected Versions
eProsima Fast-DDS < 2.6.12 (affected), >= 2.7.0, < 2.14.6 (affected), >= 3.0.0, < 3.2.4 (affected), >= 3.3.0, < 3.3.1 (affected), >= 3.4.0, < 3.4.2 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityGitHub, Inc. · Vendor · USA
Reserved2026-01-07T21:50:39
Published2026-09-09T15:43:28
Last Updated2026-09-09T16:08:57

LINK COPIED TO CLIPBOARD