{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ion-dtn--4.2.1-a.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:nasa:ion-dtn:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-75584"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["ION-DTN (\u003c 4.2.1-a.1)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability"],"_cs_type":"advisory","_cs_vendors":["NASA"],"content_html":"\u003cp\u003eION-DTN versions prior to 4.2.1-a.1 contain a denial-of-service vulnerability triggered by improper input validation within the Bundle Protocol version 7 (BPv7) stack. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted BPv7 bundle containing a zero-length payload. The vulnerability resides in the canonicalizePayloadBlock() function located in bpsec_util.c, which passes the payload length to the zco_clone() function without verification. This lack of validation triggers a failed CHKZERO assertion, resulting in a call to sm_Abort() and the immediate termination of the ION process via a SIGABRT signal. Because the crash occurs before HMAC verification is performed, no valid credentials or keys are required to successfully trigger the service interruption, making the system highly susceptible to remote disruption.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a network-exposed instance running an affected version of ION-DTN (\u0026lt; 4.2.1-a.1).\u003c/li\u003e\n\u003cli\u003eAttacker prepares a malicious BPv7 bundle packet with a payload length field explicitly set to zero.\u003c/li\u003e\n\u003cli\u003eAttacker transmits the malformed bundle over the network to the target ION-DTN service endpoint.\u003c/li\u003e\n\u003cli\u003eThe target system receives the packet and initiates processing within the Bundle Protocol (BP) stack.\u003c/li\u003e\n\u003cli\u003eThe canonicalizePayloadBlock() function processes the bundle and invokes zco_clone() with the unchecked zero-length value.\u003c/li\u003e\n\u003cli\u003eThe zco_clone() function triggers a CHKZERO assertion failure due to the invalid length.\u003c/li\u003e\n\u003cli\u003eThe process calls sm_Abort() and terminates abruptly via SIGABRT, resulting in a denial of service.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the immediate, unauthenticated termination of the ION-DTN process. This impact is significant for mission-critical deployments using Delay-Tolerant Networking (DTN) protocols where uptime is essential for data relay operations. If exploited, the service remains offline until manual intervention restarts the process, potentially leading to critical data loss or communication outages across affected network nodes.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for administrators of ION-DTN systems:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of ION-DTN to version 4.2.1-a.1 or later to remediate the vulnerability identified in CVE-2026-75584.\u003c/li\u003e\n\u003cli\u003eImplement network-level filtering to restrict access to ION-DTN services to known and trusted peer nodes to mitigate the impact of unauthenticated access.\u003c/li\u003e\n\u003cli\u003eDeploy monitoring systems to detect and alert on abnormal process termination events (e.g., SIGABRT) or unexpected service restarts in the ION environment.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T17:07:19Z","date_published":"2026-09-10T17:07:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ion-dtn-dos/","summary":"ION-DTN versions prior to 4.2.1-a.1 are vulnerable to a remote denial-of-service attack, allowing unauthenticated attackers to terminate the process by sending a malformed BPv7 bundle.","title":"Denial of Service in ION-DTN via Zero-Length Payload","url":"https://feed.craftedsignal.io/briefs/2026-09-ion-dtn-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - ION-DTN (\u003c 4.2.1-A.1)","version":"https://jsonfeed.org/version/1.1"}