CVE-2026-22590 Overview
CVE-2026-22590 is an out-of-bounds read vulnerability in eprosima Fast DDS, a C++ implementation of the Object Management Group's Data Distribution Service (DDS) standard. The flaw resides in the processing of Real-Time Publish-Subscribe (RTPS) DATA_FRAG submessages. A remote attacker can craft a malicious fragment that forces the receiver to read past the UDP datagram buffer into adjacent heap memory. In Discovery Server deployments, leaked heap bytes can be relayed to other participants, exposing pointer values that may aid Address Space Layout Randomization (ASLR) bypass. The issue affects Fast DDS versions prior to 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2.
Critical Impact
Unauthenticated remote attackers can trigger heap memory disclosure and denial of service across DDS participants, undermining confidentiality and availability of middleware-connected systems.
Affected Products
- eprosima Fast DDS versions prior to 2.6.12
- eprosima Fast DDS versions prior to 2.14.6, 3.2.4, and 3.3.1
- eprosima Fast DDS versions prior to 3.4.2
Discovery Timeline
- 2026-09-09 - CVE CVE-2026-22590 published to NVD
- 2026-09-09 - Last updated in NVD database
Technical Details for CVE-2026-22590
Vulnerability Analysis
The vulnerability lives in the RTPS DATA_FRAG submessage handler used to reassemble fragmented DDS samples. An attacker crafts a DATA_FRAG submessage that declares a large sampleSize while carrying only a small actual payload. By setting fragmentsInSubmessage so the receiver treats the packet as the LAST fragment, execution enters a code path that trusts the declared sampleSize when computing incoming_length.
Fast DDS then invokes memcpy() without validating that incoming_data.length >= incoming_length. CacheChange_t::add_fragments() reads past the received UDP datagram buffer into adjacent heap memory and copies those bytes into the reassembly buffer. In Discovery Server deployments, the resulting CacheChange_t is relayed to other participants, so a newly joining participant may receive leaked heap contents such as pointer values useful for defeating ASLR.
Root Cause
The root cause is a missing bounds check on the received UDP payload length before the LAST-fragment memory copy [CWE-125]. The receiver derives the copy size from attacker-controlled protocol fields rather than the actual datagram length.
Attack Vector
Exploitation requires only network access to a vulnerable Fast DDS participant. No authentication or user interaction is needed. The attacker sends a single malformed RTPS DATA_FRAG submessage over UDP. In Discovery Server topologies, the leaked memory propagates to other participants, extending the disclosure surface across the DDS network.
No verified public proof-of-concept code is available at the time of publication. Consult the GitHub Security Advisory GHSA-7r7h-hwfj-q626 for authoritative technical details.
Detection Methods for CVE-2026-22590
Indicators of Compromise
- Inbound RTPS DATA_FRAG submessages where the declared sampleSize significantly exceeds the observed UDP payload length.
- DATA_FRAG packets with fragmentsInSubmessage values that place them on the LAST-fragment reassembly path with undersized payloads.
- Unexpected participants joining the Discovery Server followed by outbound relayed samples containing anomalous or high-entropy binary regions.
Detection Strategies
- Deploy DDS-aware network inspection to validate DATA_FRAG field consistency against actual datagram length before forwarding.
- Correlate Fast DDS process telemetry with UDP flows on RTPS ports (default 7400-7500 range) to spot malformed submessage patterns.
- Alert on Fast DDS process crashes, segmentation faults, or address sanitizer reports involving CacheChange_t::add_fragments().
Monitoring Recommendations
- Enable verbose Fast DDS logging on Discovery Servers and archive fragment reassembly warnings for review.
- Monitor participant discovery events and flag joins from unexpected source addresses immediately preceding relayed sample bursts.
- Baseline normal DATA_FRAG sizes per topic and alert on statistical outliers in fragment metadata.
How to Mitigate CVE-2026-22590
Immediate Actions Required
- Upgrade all Fast DDS deployments to 2.6.12, 2.14.6, 3.2.4, 3.3.1, or 3.4.2 depending on the current release branch.
- Inventory every application and robotics component that embeds Fast DDS, including transitive dependencies in ROS 2 stacks.
- Restrict RTPS UDP traffic to trusted network segments using firewalls or VLAN segmentation until patching completes.
Patch Information
eprosima has released fixed builds in versions 2.6.12, 2.14.6, 3.2.4, 3.3.1, and 3.4.2. The patches add proper bounds validation in CacheChange_t::add_fragments() before the LAST-fragment memcpy() operation. Refer to the GitHub Security Advisory GHSA-7r7h-hwfj-q626 for release notes and commit references.
Workarounds
- Enable DDS Security to require authentication and encryption on RTPS traffic, limiting who can send DATA_FRAG submessages.
- Isolate Discovery Servers on dedicated management networks unreachable from untrusted hosts.
- Apply network ACLs on RTPS discovery and user traffic ports to permit only known participant IP addresses.
# Configuration example - restrict RTPS traffic to trusted subnet
iptables -A INPUT -p udp --dport 7400:7500 -s 10.0.0.0/24 -j ACCEPT
iptables -A INPUT -p udp --dport 7400:7500 -j DROP
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
