Description
OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). Prior to 3.34.0, a network attacker can crash a reachable OpenDDS participant by sending a malformed RTPS UDP submessage whose crafted length or sequence-number state causes dds/DCPS/transport/rtps_udp/RtpsUdpReceiveStrategy.cpp in RtpsUdpReceiveStrategy::handle_input() to advance ACE_Message_Block::rd_ptr() beyond valid data. The parser can then call dds/DCPS/transport/rtps_udp/RtpsSampleHeader.cpp in RtpsSampleHeader::init(), which dereferences the invalid read pointer without first validating it against wr_ptr() or ensuring that a complete submessage header remains. The resulting SIGSEGV occurs in the receive thread, terminates the DDS process, and destroys the DDS entities hosted by that participant. No authentication, prior protocol state, or victim interaction is required. This issue is fixed in version 3.34.0.
Published: 2026-09-17
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Denial of Service
Action: Apply Patch
AI Analysis

Impact

OpenDDS is a C++ implementation of the OMG Data Distribution Service that allows participants to exchange messages over a network. A malformed RTPS UDP submessage containing a crafted length or sequence number can cause the library to read past the end of a message buffer. The parser then dereferences this invalid pointer, triggering a segmentation fault in the receive thread. The fault terminates the DDS process and removes all entities for that participant. Because the attack requires only a crafted packet sent over the network, no authentication or prior state is needed, giving any remote attacker the ability to bring a reachable OpenDDS instance down. The flaw is a CWE‑125 out‑of‑bounds read.

Affected Systems

The vulnerability affects all OpenDDS installations with a version earlier than 3.34.0, regardless of platform. The issue is fixed in the 3.34.0 release, so any deployment running 3.34.0 or later is no longer susceptible.

Risk and Exploitability

The CVSS v3.1 score of 8.7 places the flaw in the high severity range, while the EPSS score of less than 1% indicates a low probability of exploitation in the wild. It is not currently listed in the CISA KEV catalog. An attacker can exploit the vulnerability remotely over the standard RTPS UDP ports with a single crafted packet, without any authentication or additional interactions. Successful exploitation causes a denial of service by crashing the participant process and tearing down the DDS entities it hosts.

Generated by OpenCVE AI on September 19, 2026 at 00:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenDDS to version 3.34.0 or later, which contains the patch for the out‑of‑bounds read.
  • If upgrade is not immediately possible, limit network exposure by blocking UDP traffic on the RTPS port (17000 and any configured RTPS port) from untrusted hosts.
  • Monitor OpenDDS logs or system metrics for unexpected segmentation faults or abrupt process terminations and alert administrators when they occur.

Generated by OpenCVE AI on September 19, 2026 at 00:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Opendds
Opendds opendds
Vendors & Products Opendds
Opendds opendds

Thu, 17 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Description OpenDDS is an open source C++ implementation of the Object Management Group (OMG) Data Distribution Service (DDS). Prior to 3.34.0, a network attacker can crash a reachable OpenDDS participant by sending a malformed RTPS UDP submessage whose crafted length or sequence-number state causes dds/DCPS/transport/rtps_udp/RtpsUdpReceiveStrategy.cpp in RtpsUdpReceiveStrategy::handle_input() to advance ACE_Message_Block::rd_ptr() beyond valid data. The parser can then call dds/DCPS/transport/rtps_udp/RtpsSampleHeader.cpp in RtpsSampleHeader::init(), which dereferences the invalid read pointer without first validating it against wr_ptr() or ensuring that a complete submessage header remains. The resulting SIGSEGV occurs in the receive thread, terminates the DDS process, and destroys the DDS entities hosted by that participant. No authentication, prior protocol state, or victim interaction is required. This issue is fixed in version 3.34.0.
Title OpenDDS: out-of-bounds `rd_ptr` dereference in `RtpsSampleHeader::init` — triggered by malformed RTPS submessage, remotely exploitable denial of service
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T14:44:20.451Z

Reserved: 2026-06-08T18:41:27.723Z

Link: CVE-2026-52836

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T18:16:44.697

Modified: 2026-09-24T21:20:08.527

Link: CVE-2026-52836

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T00:30:16Z

Weaknesses