OCI OpenDDS versions prior to 3.18.1 do not handle a length parameter consistent with the actual length of the associated data, which may allow an attacker to remotely execute arbitrary code.
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-38445.json"