An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead to thread crashes or cause denial of service conditions.
CVE ID: CVE-2024-10838
CVSS Base Severity: HIGH
CVSS Base Score: 8.8
CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N
Vendor: Eclipse Foundation
Product: Eclipse Cyclone DDS
EPSS Score: 0.05% (probability of being exploited)
EPSS Percentile: 13.64% (scored less or equal to compared to others)
EPSS Date: 2025-04-10 (when was this score calculated)