CVE-2026-84484
ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.
Schwachstellenklasse
ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.
Quellen
- https://github.com/nasa-jpl/ION-DTN
- https://github.com/nasa-jpl/ION-DTN/blob/ion-open-source-4.1.4/ici/library/ion.c#L1693
- https://github.com/nasa-jpl/ION-DTN/blob/ion-open-source-4.1.4/ici/library/platform.c#L1982
- https://github.com/nasa-jpl/ION-DTN/commit/d52d22bdd383798712357f86a2778757f740e812
- https://github.com/nasa-jpl/ION-DTN/releases/tag/ion-open-source-4.2.0
- https://github.com/nasa-jpl/ION-DTN/security/advisories/GHSA-85pw-28vw-2jf7
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.