Opendds · Opendds · CVE-2026-52836
**Name of the Vulnerable Software and Affected Versions**
OpenDDS versions prior to 3.34.0
**Description**
A network attacker can crash a reachable participant by sending a malformed RTPS UDP submessage. A crafted length or sequence-number state causes the `handle input()` function in `RtpsUdpReceiveStrategy.cpp` to advance the `rd ptr()` of `ACE Message Block` beyond valid data. Subsequently, the `init()` function in `RtpsSampleHeader.cpp` dereferences this invalid read pointer without validating it against `wr ptr()` or ensuring a complete submessage header remains. This leads to a SIGSEGV (segmentation fault), which is a specific error that occurs when a program attempts to access a memory location that it is not allowed to access, terminating the process and destroying hosted entities. No authentication or victim interaction is required.
**Recommendations**
Update to version 3.34.0.