Loading
An integer underflow during deserialization may allow any unauthenticated user to read out of bounds heap memory. This may result into secret data or pointers revealing the layout of the address space to be included into a deserialized data structure, which may potentially lead to thread crashes or cause denial of service conditions.
Use CWE-191, Eclipse vendor hub and Cyclone Data Distribution Service product page to widen CVE-2024-10838 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2025-67109, CVE-2020-18735 and CVE-2020-18734 for nearby disclosures in the same product family.