Critical severity9.1NVD Advisory· Published Mar 12, 2025· Updated Jun 17, 2026
CVE-2024-10838
CVE-2024-10838
Description
An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead to thread crashes or cause denial of service conditions.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Eclipse Foundation/Eclipse Cyclone DDSv5Range: 0
- Range: <0.10.5
- cpe:2.3:a:eclipse:cyclone_data_distribution_service:*:*:*:*:*:*:*:*Range: <0.10.5
Patches
Vulnerability mechanics
References
3- github.com/eclipse-cyclonedds/cyclonedds/releases/tag/0.10.5nvdPatch
- github.com/eclipse-cyclonedds/cyclonedds/security/advisories/GHSA-6jj6-w25p-jc42nvdExploitVendor Advisory
- gitlab.eclipse.org/security/cve-assignement/-/issues/46nvdIssue TrackingVendor Advisory
News mentions
0No linked articles in our index yet.