CVE-2024-10838

An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead to thread crashes or cause denial of service conditions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:eclipse:cyclone_data_distribution_service:*:*:*:*:*:*:*:*

History

31 Jul 2025, 16:33

Type Values Removed Values Added
First Time Eclipse cyclone Data Distribution Service
Eclipse
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
CPE cpe:2.3:a:eclipse:cyclone_data_distribution_service:*:*:*:*:*:*:*:*
References () https://gitlab.eclipse.org/security/cve-assignement/-/issues/46 - () https://gitlab.eclipse.org/security/cve-assignement/-/issues/46 - Issue Tracking, Vendor Advisory
References () https://github.com/eclipse-cyclonedds/cyclonedds/security/advisories/GHSA-6jj6-w25p-jc42 - () https://github.com/eclipse-cyclonedds/cyclonedds/security/advisories/GHSA-6jj6-w25p-jc42 - Vendor Advisory, Exploit
References () https://github.com/eclipse-cyclonedds/cyclonedds/releases/tag/0.10.5 - () https://github.com/eclipse-cyclonedds/cyclonedds/releases/tag/0.10.5 - Patch

12 Mar 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-12 13:15

Updated : 2025-07-31 16:33


NVD link : CVE-2024-10838

Mitre link : CVE-2024-10838


JSON object : View

Products Affected

eclipse

  • cyclone_data_distribution_service
CWE

No CWE.