ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 03 Sep 2026 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Nasajpl
Nasajpl iondtn |
|
| Vendors & Products |
Nasajpl
Nasajpl iondtn |
Wed, 02 Sep 2026 01:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | ION-DTN versions before 4.2.0 contain an out-of-bounds read vulnerability in the decodeSdnv function that allows unauthenticated remote attackers to read memory by sending truncated SDNV values. Attackers can send a UDP datagram to the LTP link service input port with a truncated SDNV to trigger reads up to nine bytes past buffer boundaries and underflow byte counters. | |
| Title | ION-DTN before 4.2.0 Out-of-Bounds Read via decodeSdnv | |
| Weaknesses | CWE-125 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-04T02:22:08.836Z
Reserved: 2026-09-01T20:37:00.841Z
Link: CVE-2026-84484
No data.
Status : Received
Published: 2026-09-02T02:17:20.450
Modified: 2026-09-02T02:17:20.450
Link: CVE-2026-84484
No data.
OpenCVE Enrichment
Updated: 2026-09-03T16:00:07Z
Weaknesses