#VU125728 Heap-based buffer overflow in Fast DDS - CVE-2025-62799
Published: April 9, 2026
Fast DDS
eProsima
Description
The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.
The vulnerability exists due to a heap-based buffer overflow in the RTPS DATA_FRAG receive path when processing a malformed RTPS DATA_FRAG packet. A remote attacker can send a specially crafted DATA_FRAG packet with crafted fragmentSize and sampleSize values to execute arbitrary code or cause a denial of service.
The issue affects reachable RELIABLE subscribers receiving RTPS over UDP, and no user interaction is required.