📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Artificial Intelligence and Technology HIGH 18m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 16h Global apt Critical Infrastructure CRITICAL 16h Global vulnerability Artificial Intelligence and Technology HIGH 18m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 16h Global apt Critical Infrastructure CRITICAL 16h Global vulnerability Artificial Intelligence and Technology HIGH 18m Global general Technology and Artificial Intelligence MEDIUM 3h Global general Technology and Artificial Intelligence HIGH 4h Global vulnerability Higher Education CRITICAL 13h Global data_breach Government HIGH 14h Global supply_chain Software Development and Open Source Communities CRITICAL 14h Global malware Software Development CRITICAL 14h Global phishing Multiple Sectors HIGH 15h Global vulnerability Web Applications CRITICAL 16h Global apt Critical Infrastructure CRITICAL 16h
Vulnerabilities

CVE-2025-64438

High
Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group ). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a remotely triggerable Out-of-Memory
CWE-835 — Weakness Type
Published: Feb 3, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
7.5
🔗 NVD Official
📄 Description (English)

Fast DDS is a C++ implementation of the DDS (Data Distribution Service) standard of the OMG (Object Management Group
). Prior to versions 3.4.1, 3.3.1, and 2.6.11, a remotely triggerable Out-of-Memory (OOM) denial-of-service exists in Fast
-DDS when processing RTPS GAP submessages under RELIABLE QoS. By sending a tiny GAP packet with a huge gap range (`gapList
.base - gapStart`), an attacker drives `StatefulReader::processGapMsg()` into an unbounded loop that inserts millions of s
equence numbers into `WriterProxy::changes_received_` (`std::set`), causing multi-GB heap growth and process termination.
No authentication is required beyond network reachability to the reader on the DDS domain. In environments without an RSS
limit (non-ASan / unlimited), memory consumption was observed to rise to ~64 GB. Versions 3.4.1, 3.3.1, and 2.6.11 patch t
he issue.

🤖 AI Executive Summary

Fast DDS versions prior to 3.4.1, 3.3.1, and 2.6.11 contain a critical remote denial-of-service vulnerability in RTPS GAP submessage processing that triggers unbounded memory allocation, potentially consuming up to 64GB of heap memory and causing process termination. The vulnerability requires only network reachability to a DDS reader and no authentication, making it highly exploitable in networked industrial and IoT environments. Organizations using Fast DDS in critical infrastructure must immediately patch to mitigate service disruption risks.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: May 2, 2026 13:16
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi critical infrastructure sectors: (1) Energy/ARAMCO and downstream petroleum operations utilizing DDS for SCADA and industrial control systems; (2) Telecommunications (STC, Mobily, Zain) deploying DDS in 5G/6G network management and IoT platforms; (3) Government agencies and NCA infrastructure using DDS for distributed command-and-control systems; (4) Healthcare institutions implementing DDS-based medical device networks and patient monitoring systems; (5) Financial institutions (SAMA-regulated banks) using DDS for real-time transaction processing and market data distribution. The attack requires only network access without authentication, making it particularly dangerous in environments with inadequate network segmentation. Service disruption could cascade across interconnected systems in critical infrastructure.
🏢 Affected Saudi Sectors
Energy/Oil & Gas (ARAMCO, downstream operations) Telecommunications (STC, Mobily, Zain) Government/Critical Infrastructure (NCA, defense) Healthcare (hospital networks, medical devices) Financial Services (SAMA-regulated banks) Water/Utilities Transportation/Logistics
⚖️ Saudi Risk Score (AI)
8.2
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all Fast DDS deployments across your infrastructure using network scanning and software inventory tools
2. Isolate or restrict network access to DDS readers/writers to trusted networks only using firewall rules
3. Implement network segmentation to prevent untrusted sources from reaching DDS domains
4. Monitor system memory usage on DDS processes for anomalous growth patterns

PATCHING GUIDANCE:
1. Upgrade Fast DDS to version 3.4.1, 3.3.1, or 2.6.11 immediately
2. Test patches in non-production environments first, particularly for critical infrastructure
3. Plan maintenance windows for production systems to minimize service disruption
4. Verify patch application by checking version strings and restarting DDS services

COMPENSATING CONTROLS (if patching delayed):
1. Implement strict ingress filtering at network boundaries to block RTPS traffic from untrusted sources
2. Deploy DDS traffic inspection rules to detect and block malformed GAP submessages with suspicious gap ranges
3. Configure process-level resource limits (ulimit, cgroups) to prevent memory exhaustion beyond defined thresholds
4. Enable detailed logging of RTPS message processing to detect attack patterns

DETECTION RULES:
1. Alert on RTPS GAP submessages where (gapList.base - gapStart) exceeds 1,000,000 sequence numbers
2. Monitor DDS process memory growth exceeding 500MB per minute
3. Track RTPS protocol errors and malformed message rejections
4. Correlate memory spikes with specific source IP addresses sending RTPS traffic
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع نشرات Fast DDS عبر البنية التحتية الخاصة بك باستخدام أدوات المسح الشبكي وجرد البرامج
2. عزل أو تقييد الوصول إلى الشبكة لقارئي/كاتبي DDS إلى الشبكات الموثوقة فقط باستخدام قواعد جدار الحماية
3. تنفيذ تقسيم الشبكة لمنع المصادر غير الموثوقة من الوصول إلى مجالات DDS
4. مراقبة استخدام ذاكرة النظام في عمليات DDS للكشف عن أنماط النمو الشاذة

إرشادات التصحيح:
1. ترقية Fast DDS إلى الإصدار 3.4.1 أو 3.3.1 أو 2.6.11 فوراً
2. اختبار التصحيحات في بيئات غير الإنتاج أولاً، خاصة للبنية التحتية الحرجة
3. التخطيط لنوافذ الصيانة لأنظمة الإنتاج لتقليل انقطاع الخدمة
4. التحقق من تطبيق التصحيح بفحص سلاسل الإصدار وإعادة تشغيل خدمات DDS

الضوابط البديلة (إذا تأخر التصحيح):
1. تنفيذ تصفية الدخول الصارمة على حدود الشبكة لحظر حركة RTPS من مصادر غير موثوقة
2. نشر قواعد فحص حركة DDS للكشف عن رسائل GAP المشوهة وحظرها برطولة فجوة مريبة
3. تكوين حدود موارد على مستوى العملية (ulimit، cgroups) لمنع استنزاف الذاكرة بما يتجاوز الحدود المحددة
4. تفعيل السجلات التفصيلية لمعالجة رسائل RTPS للكشف عن أنماط الهجوم

قواعد الكشف:
1. تنبيه رسائل RTPS GAP حيث (gapList.base - gapStart) يتجاوز 1,000,000 رقم تسلسلي
2. مراقبة نمو ذاكرة عملية DDS يتجاوز 500 ميجابايت في الدقيقة
3. تتبع أخطاء بروتوكول RTPS ورفض الرسائل المشوهة
4. ربط ارتفاعات الذاكرة بعناوين IP المصدر المحددة التي ترسل حركة RTPS
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.12.6.1 - Management of technical vulnerabilities in network services ECC 2024 A.12.2.1 - Monitoring and control of network services ECC 2024 A.8.2.3 - Segregation of networks and systems ECC 2024 A.12.4.1 - Event logging and monitoring
🔵 SAMA CSF
ID.RA-1 - Asset Management and vulnerability identification PR.IP-12 - System and information integrity monitoring DE.CM-1 - Network monitoring and anomaly detection RS.MI-2 - Incident response and containment procedures
🟡 ISO 27001:2022
A.12.2.1 - Monitoring of information systems A.12.6.1 - Management of technical vulnerabilities A.13.1.1 - Network security perimeter controls A.12.4.1 - Event logging and monitoring
🟣 PCI DSS v4.0.1
Requirement 6.2 - Security patches and vulnerability management Requirement 11.2 - Vulnerability scanning and assessment Requirement 12.2 - Configuration standards for systems
📦 Affected Products / CPE 3 entries
eprosima:fast_dds
eprosima:fast_dds
eprosima:fast_dds:3.4.0
📊 CVSS Score
7.5
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityN — None / Network
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.5
CWECWE-835
EPSS0.03%
Exploit No
Patch ✓ Yes
Published 2026-02-03
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
8.2
/ 10.0 — Saudi Risk
Priority: CRITICAL
🏷️ Tags
patch-available CWE-835
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.