HIGH 8.7 NVD
CVE-2026-84484
ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory
ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.
References
- https://github.com/nasa-jpl/ION-DTN
- https://github.com/nasa-jpl/ION-DTN/blob/ion-open-source-4.1.4/ici/library/ion.c#L1693
- https://github.com/nasa-jpl/ION-DTN/blob/ion-open-source-4.1.4/ici/library/platform.c#L198
- https://github.com/nasa-jpl/ION-DTN/commit/d52d22bdd383798712357f86a2778757f740e812
- https://github.com/nasa-jpl/ION-DTN/releases/tag/ion-open-source-4.2.0
This high severity vulnerability with a CVSS score of 8.7 was published on 2026-09-02 via NVD.
vulnfeed aggregates 11552 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.