top of page
perceptive_background_267k.jpg

ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory…

Published:

2 september 2026 om 00:00:00

Alert date:

2 september 2026 om 05:01:30

Source:

nvd.nist.gov

Click to open the original link from this advisory

Network Infrastructure, Critical Infrastructure

ION-DTN versions prior to 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function. Unauthenticated remote attackers can exploit this by sending truncated SDNV values via UDP datagrams to the LTP link service input port. The vulnerability can trigger memory reads up to nine bytes past buffer boundaries and cause byte counter underflows. No authentication is required to exploit this flaw, making it accessible to any network-adjacent or remote attacker. The vulnerability has been patched in ION-DTN version 4.2.0. ION-DTN is NASA JPL's open-source implementation of the Delay-Tolerant Networking (DTN) protocol, commonly used in space communications infrastructure. A fix commit is available on GitHub along with a security advisory via GHSA-85pw-28vw-2jf7.

Technical details

Mitigation steps:

Affected products:

ION-DTN versions before 4.2.0

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page