CVE-2025-62602 - CVE House
Back to Database
Status published Low CVE-2025-62602

FastDDS has heap buffer overflow in readData via Manipulated DATA Submessage when DDS Security is enabled

Vulnerability Description

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, when the security mode is enabled, modifying the DATA Submessage within an SPDP packet sent by a publisher causes a heap buffer overflow, resulting in remote termination of Fast-DDS. If the fields of `PID_IDENTITY_TOKEN` or `PID_PERMISSIONS_TOKEN` in the DATA Submessage are tampered with — specially `readOctetVector` reads an unchecked `vecsize` that is propagated unchanged into `readData` as the `length` parameter — the attacker-contro lled `vecsize` can trigger a 32-bit integer overflow during the `length` calculation. That overflow can cause large alloca tion attempt that quickly leads to OOM, enabling a remotely-triggerable denial-of-service and remote process termination. Versions 3.4.1, 3.3.1, and 2.6.11 patch the issue.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-62602

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Fast-DDS
Vulnerable Versions:
3.4.0, 3.0.0, 0

Timeline

Official Publish: February 3rd, 2026
Last Modified: February 3rd, 2026
Added to House: July 22nd, 2026

CVSS Vectors

Weaknesses (CWE)