


Perceptive Security
SOC/SIEM Consultancy

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory…
Published:
2 september 2026 om 00:00:00
Alert date:
2 september 2026 om 05:01:30
Source:
nvd.nist.gov
Network Infrastructure, Critical Infrastructure
ION-DTN versions prior to 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function. Unauthenticated remote attackers can exploit this by sending truncated SDNV values via UDP datagrams to the LTP link service input port. The vulnerability can trigger memory reads up to nine bytes past buffer boundaries and cause byte counter underflows. No authentication is required to exploit this flaw, making it accessible to any network-adjacent or remote attacker. The vulnerability has been patched in ION-DTN version 4.2.0. ION-DTN is NASA JPL's open-source implementation of the Delay-Tolerant Networking (DTN) protocol, commonly used in space communications infrastructure. A fix commit is available on GitHub along with a security advisory via GHSA-85pw-28vw-2jf7.
Technical details
Mitigation steps:
Affected products:
ION-DTN versions before 4.2.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-84484
https://github.com/nasa-jpl/ION-DTN
https://github.com/nasa-jpl/ION-DTN/blob/ion-open-source-4.1.4/ici/library/ion.c#L1693
https://github.com/nasa-jpl/ION-DTN/blob/ion-open-source-4.1.4/ici/library/platform.c#L1982
https://github.com/nasa-jpl/ION-DTN/commit/d52d22bdd383798712357f86a2778757f740e812
https://github.com/nasa-jpl/ION-DTN/releases/tag/ion-open-source-4.2.0
https://github.com/nasa-jpl/ION-DTN/security/advisories/GHSA-85pw-28vw-2jf7
https://www.vulncheck.com/advisories/ion-dtn-before-4.2.0-out-of-bounds-read-via-decodesdnv
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
