PT-2026-95019 · Opendds · Opendds
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenDDS versions prior to 3.34.0
Description
A network attacker can crash a reachable participant by sending a malformed RTPS UDP submessage. A crafted length or sequence-number state causes the
handle input() function in RtpsUdpReceiveStrategy.cpp to advance the rd ptr() of ACE Message Block beyond valid data. Subsequently, the init() function in RtpsSampleHeader.cpp dereferences this invalid read pointer without validating it against wr ptr() or ensuring a complete submessage header remains. This leads to a SIGSEGV (segmentation fault), which is a specific error that occurs when a program attempts to access a memory location that it is not allowed to access, terminating the process and destroying hosted entities. No authentication or victim interaction is required.Recommendations
Update to version 3.34.0.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opendds