#VU125726 Excessive Iteration in Fast DDS - CVE-2025-65016
Published: April 9, 2026
Fast DDS
eProsima
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to excessive iteration in StatefulReader::NotifyChanges() when processing RTPS HEARTBEAT submessages with a crafted large firstSequenceNumber value under RELIABLE QoS. A remote attacker can send a specially crafted HEARTBEAT packet to cause a denial of service.
Exploitation requires network reachability to the reader on the DDS domain and endpoint matching to have created a WriterProxy on the subscriber.