Vulnerability record · CVE-2023-42459 · published 16 October 2023
CVE-2023-42459: Eprosima fast dds double free vulnerability
Eprosima · Fast Dds
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). In affected versions specific DATA submessages can be sent to a discovery locator which may trigger a free error. This can remotely crash any Fast-DDS process. The call to free() could potentially leave the pointer in the attackers control which could lead to a double free. This issue has been addressed in versions 2.12.0, 2.11.3, 2.10.3, and 2.6.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
Description
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group). In affected versions specific DATA submessages can be sent to a discovery locator which may trigger a free error. This can remotely crash any Fast-DDS process. The call to free() could potentially leave the pointer in the attackers control which could lead to a double free. This issue has been addressed in versions 2.12.0, 2.11.3, 2.10.3, and 2.6.7. Users are advised to upgrade. There are no known workarounds for this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://github.com/eProsima/Fast-DDS/issues/3207 | ExploitIssue Tracking |
| https://github.com/eProsima/Fast-DDS/pull/3824 | Patch |
| https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-gq8g-fj58-22gm | Vendor Advisory |
| https://www.debian.org/security/2023/dsa-5568 | Mailing List |
| https://github.com/eProsima/Fast-DDS/issues/3207 | ExploitIssue Tracking |
| https://github.com/eProsima/Fast-DDS/pull/3824 | Patch |
| https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-gq8g-fj58-22gm | Vendor Advisory |
| https://www.debian.org/security/2023/dsa-5568 | Mailing List |
Track CVE-2023-42459 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-42459), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.