CVE-2026-75584
ION-DTN < 4.2.1-a.1 Denial of Service via canonicalizePayloadBlock() Assertion
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsec_util.c passes bundle->payload.length to zco_clone() without validating it against zero, causing a failed CHKZERO assertion that triggers sm_Abort() and terminates the process with SIGABRT before any HMAC verification occurs, requiring no valid key or credential to exploit.
| CWE | CWE-617 |
| Vendor | nasa-jpl |
| Product | ion-dtn |
| Published | Sep 10, 2026 |
Stay Ahead of the Next One
Get instant alerts for nasa-jpl ion-dtn
Be the first to know when new high vulnerabilities affecting nasa-jpl ion-dtn are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
nasa-jpl / ION-DTN
0 โค 4.2.0
References
Credits
Asadbek Fatullayev VulnCheck