{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-07-01T22:32:43.661","vulnerabilities":[{"cve":{"id":"CVE-2023-42459","sourceIdentifier":"security-advisories@github.com","published":"2023-10-16T21:15:10.923","lastModified":"2026-06-17T06:23:52.630","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). In affected versions specific DATA submessages can be sent to a discovery locator which may trigger a free error. This can remotely crash any Fast-DDS process. The call to free() could potentially leave the pointer in the attackers control which could lead to a double free. This issue has been addressed in versions 2.12.0, 2.11.3, 2.10.3, and 2.6.7. Users are advised to upgrade. There are no known workarounds for this vulnerability."},{"lang":"es","value":"Fast DDS es una implementación en C++ del estándar DDS (Servicio de Distribución de Datos) de OMG (Object Management Group). En las versiones afectadas, se pueden enviar submensajes de DATOS específicos a un localizador de descubrimiento que puede provocar un error free. Esto puede bloquear de forma remota cualquier proceso Fast-DDS. La llamada a free() podría potencialmente dejar el puntero en el control del atacante, lo que podría conducir a un doble free. Este problema se solucionó en las versiones 2.12.0, 2.11.3, 2.10.3 y 2.6.7. Se recomienda a los usuarios que actualicen. No se conocen workarounds para esta vulnerabilidad."}],"affected":[{"source":"security-advisories@github.com","affectedData":[{"vendor":"eProsima","product":"Fast-DDS","versions":[{"version":">= 2.11.0, <= 2.11.1","status":"affected"},{"version":">= 2.10.0, < 2.10.3","status":"affected"},{"version":"< 2.6.7","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security-advisories@github.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H","baseScore":8.6,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"LOW","integrityImpact":"LOW","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":4.7},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","baseScore":7.5,"baseSeverity":"HIGH","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"NONE","availabilityImpact":"HIGH"},"exploitabilityScore":3.9,"impactScore":3.6}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-11-27T16:15:17.004500Z","id":"CVE-2023-42459","options":[{"exploitation":"none"},{"automatable":"yes"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security-advisories@github.com","type":"Secondary","description":[{"lang":"en","value":"CWE-415"},{"lang":"en","value":"CWE-416"},{"lang":"en","value":"CWE-590"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-415"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*","versionEndExcluding":"2.6.7","matchCriteriaId":"B6D03699-CB0F-4A0D-BDB6-1007A9D669EE"},{"vulnerable":true,"criteria":"cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*","versionStartIncluding":"2.10.0","versionEndExcluding":"2.10.3","matchCriteriaId":"C24C066C-7447-4106-A5BA-EEE3EF108404"},{"vulnerable":true,"criteria":"cpe:2.3:a:eprosima:fast_dds:*:*:*:*:*:*:*:*","versionStartIncluding":"2.11.0","versionEndIncluding":"2.11.1","matchCriteriaId":"1ACA728D-A75E-4969-A636-633E0460FED6"}]}]}],"references":[{"url":"https://github.com/eProsima/Fast-DDS/issues/3207","source":"security-advisories@github.com","tags":["Exploit","Issue Tracking"]},{"url":"https://github.com/eProsima/Fast-DDS/pull/3824","source":"security-advisories@github.com","tags":["Patch"]},{"url":"https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-gq8g-fj58-22gm","source":"security-advisories@github.com","tags":["Vendor Advisory"]},{"url":"https://www.debian.org/security/2023/dsa-5568","source":"security-advisories@github.com","tags":["Mailing List"]},{"url":"https://github.com/eProsima/Fast-DDS/issues/3207","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Issue Tracking"]},{"url":"https://github.com/eProsima/Fast-DDS/pull/3824","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch"]},{"url":"https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-gq8g-fj58-22gm","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]},{"url":"https://www.debian.org/security/2023/dsa-5568","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List"]}]}}]}