High severity7.5NVD Advisory· Published Sep 10, 2026· Updated Sep 10, 2026
CVE-2026-75584
CVE-2026-75584
Description
ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsec_util.c passes bundle->payload.length to zco_clone() without validating it against zero, causing a failed CHKZERO assertion that triggers sm_Abort() and terminates the process with SIGABRT before any HMAC verification occurs, requiring no valid key or credential to exploit.
Affected products
2Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.