---
id: CVE-2025-61910
title: >-
  The NASA’s Interplanetary Overlay Network (ION) is an implementation of
  Delay/Disruption Tolerant Networking (DTN)
summary: >-
  The NASA’s Interplanetary Overlay Network (ION) is an implementation of
  Delay/Disruption Tolerant Networking (DTN). A BPv7 bundle with a malformed
  extension block causes uncontrolled memory allocation inside ION-DTN 4.1.3s,
  leading to re…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-789
published: '2025-10-07'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T13:10:00.200'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-61910'
references:
  - url: >-
      https://github.com/nasa-jpl/ION-DTN/blob/ion-open-source-4.1.3s/bpv7/library/bei.c#L758-L769
    label: security-advisories@github.com
  - url: >-
      https://github.com/nasa-jpl/ION-DTN/security/advisories/GHSA-xm96-38vj-h28h
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.00355
epssPercentile: 0.27103
ingestedAt: '2026-10-08T13:42:54.981Z'
---

## Overview

The NASA’s Interplanetary Overlay Network (ION) is an implementation of Delay/Disruption Tolerant Networking (DTN). A BPv7 bundle with a malformed extension block causes uncontrolled memory allocation inside ION-DTN 4.1.3s, leading to receiver thread termination and a Denial-of-Service (DoS). The triggering bundle contains an extension block starting at `0x85070201005bbb0e20b4ea001a000927c0...`. The first byte in the extension block (0x85) indicates a CBOR array of five elements of which the first four are numbers (0x07, 0x02, 0x01, 0x00) but the fifth element is a byte string of length 27 (`0x5bbb0e20b4ea001a000927c0...`). The vulnerability seems to be due to processing the fifth element of the array (i.e., the byte string) as replacing it with a number makes the vulnerability no longer be triggered. While parsing this extension block, ION obtains a very large block length, which in the code in `bei.c`:764) seems to be passed from `blockLength` which is an unsigned int, to a 32 bit signed integer `blkSize`. The unsigned to signed conversion causes `blkSize` to hold the value of -369092043, which is then converted into a 64-bit unsigned value inside `MTAKE(blkSize)`, resulting in an attempt to allocate an unrealistic amount of memory, causing the error. As of time of publication, no known patched versions of BPv7 exist.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
