PT-2026-89421 · Nasa Jpl+1 · Ion-Dtn

·

CVE-2026-75584

·

Publicado

2026-09-10

·

Atualizado

2026-09-10

CVSS v3.1

7.5

Alta

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsec util.c passes bundle->payload.length to zco clone() without validating it against zero, causing a failed CHKZERO assertion that triggers sm Abort() and terminates the process with SIGABRT before any HMAC verification occurs, requiring no valid key or credential to exploit.

Exploit

Correção

Assertion Failure

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-75584
GHSA-9VGC-2R6G-6QWF

Produtos afetados

Ion-Dtn