GHSA-5vmj-4h65-2fh8HighCVSS 7.5

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv...

Published
September 2, 2026
Last Modified
September 2, 2026

🔗 CVE IDs covered (1)

📋 Description

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.

🔗 References (9)