CVE-2026-75584: Reachable Assertion in nasa-jpl ION-DTN
ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsec_util.c passes bundle->payload.length to zco_clone() without validating it against zero, causing a failed CHKZERO assertion that triggers sm_Abort() and terminates the process with SIGABRT before any HMAC verification occurs, requiring no valid key or credential to exploit.
AI Analysis
Technical Summary
The vulnerability in nasa-jpl's ION-DTN (<=4.2.0) arises from the canonicalizePayloadBlock() function in bpsec_util.c passing bundle->payload.length to zco_clone() without validating that the length is non-zero. When a BPv7 bundle with a zero-length payload is received, this causes a failed CHKZERO assertion, triggering sm_Abort() and terminating the process with SIGABRT. This denial of service can be exploited remotely without authentication or valid credentials, as no HMAC verification is performed before the crash.
Potential Impact
An unauthenticated remote attacker can cause a denial of service by crashing the ION-DTN process, disrupting its operation. This impact is significant given the high CVSS score of 8.7 and the lack of required credentials or user interaction for exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider implementing network-level protections to block malformed BPv7 bundles with zero-length payloads if feasible.
CVE-2026-75584: Reachable Assertion in nasa-jpl ION-DTN
Description
ION-DTN before 4.2.1-a.1 contains a denial of service vulnerability that allows unauthenticated remote attackers to crash the ION process by sending a BPv7 bundle with a zero-length payload. The canonicalizePayloadBlock() function in bpsec_util.c passes bundle->payload.length to zco_clone() without validating it against zero, causing a failed CHKZERO assertion that triggers sm_Abort() and terminates the process with SIGABRT before any HMAC verification occurs, requiring no valid key or credential to exploit.
CVSS v4.0
Score 8.7high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in nasa-jpl's ION-DTN (<=4.2.0) arises from the canonicalizePayloadBlock() function in bpsec_util.c passing bundle->payload.length to zco_clone() without validating that the length is non-zero. When a BPv7 bundle with a zero-length payload is received, this causes a failed CHKZERO assertion, triggering sm_Abort() and terminating the process with SIGABRT. This denial of service can be exploited remotely without authentication or valid credentials, as no HMAC verification is performed before the crash.
Potential Impact
An unauthenticated remote attacker can cause a denial of service by crashing the ION-DTN process, disrupting its operation. This impact is significant given the high CVSS score of 8.7 and the lack of required credentials or user interaction for exploitation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider implementing network-level protections to block malformed BPv7 bundles with zero-length payloads if feasible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-17T22:02:43.612Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6aa2b9afacd9273b4931afc2
Added to database: 09/10/2026, 14:07:43 UTC
Last enriched: 09/10/2026, 14:22:06 UTC
Last updated: 09/10/2026, 17:00:16 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.