#VU125727 Allocation of Resources Without Limits or Throttling in Fast DDS - CVE-2025-64438
Published: April 9, 2026
Fast DDS
eProsima
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in StatefulReader::processGapMsg() when processing RTPS GAP submessages under RELIABLE QoS. A remote attacker can send a specially crafted GAP packet with a huge gap range to cause a denial of service.
A single small GAP message can trigger multi-GB heap growth and process termination.