Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14684

Опубликовано: 04 июл. 2026
Источник: redhat
CVSS3: 5
EPSS Низкий

Описание

A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This manipulation of the argument numberOfSignificantValueDigits causes uncontrolled memory allocation. The attack can only be executed locally. The exploit has been published and may be used. The actual existence of this vulnerability is currently in question. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.

A flaw was found in HdrHistogram. A local attacker can exploit a vulnerability in the decodeFromByteBuffer function by manipulating the numberOfSignificantValueDigits argument. This manipulation leads to uncontrolled memory allocation, which can result in a Denial of Service (DoS) condition, making the affected system or application unavailable.

Отчет

Successful exploitation requires local access, as an attacker must be able to supply specially crafted, manipulated input directly to an application that is actively utilizing the affected HdrHistogram library. The vulnerability is strictly limited to causing a Denial of Service (DoS) via uncontrolled memory allocation. It does not allow an attacker to execute arbitrary code, escalate privileges, or access unauthorized data. Furthermore, the impact is localized to the specific application processing the malicious input, rather than causing a broader, system-wide compromise.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Fix deferred
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Fix deferred
OpenShift Service Mesh 3openshift-service-mesh/istio-ztunnel-rhel9Fix deferred
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Fix deferred
Red Hat Enterprise Linux 8HdrHistogramFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-llm-d-inference-scheduler-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-model-registry-job-async-upload-rhel9Fix deferred
Red Hat OpenShift Container Platform 4conmon-rsFix deferred
Red Hat OpenShift Update Serviceopenshift-update-service/openshift-update-service-rhel8Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2497103org.hdrhistogram/HdrHistogram: HdrHistogram: HdrHistogram: Denial of Service via uncontrolled memory allocation in decodeFromByteBuffer

EPSS

Процентиль: 2%
0.0012
Низкий

5 Medium

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 1 месяца назад

A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This manipulation of the argument numberOfSignificantValueDigits causes uncontrolled memory allocation. The attack can only be executed locally. The exploit has been published and may be used. The actual existence of this vulnerability is currently in question. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.

CVSS3: 3.3
nvd
около 1 месяца назад

A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This manipulation of the argument numberOfSignificantValueDigits causes uncontrolled memory allocation. The attack can only be executed locally. The exploit has been published and may be used. The actual existence of this vulnerability is currently in question. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.

CVSS3: 3.3
debian
около 1 месяца назад

A flaw has been found in HdrHistogram up to 2.2.2. This affects the fu ...

CVSS3: 3.3
github
около 1 месяца назад

A flaw has been found in HdrHistogram up to 2.2.2. This affects the function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This manipulation of the argument numberOfSignificantValueDigits causes uncontrolled memory allocation. The attack can only be executed locally. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet.

EPSS

Процентиль: 2%
0.0012
Низкий

5 Medium

CVSS3