Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14685

Опубликовано: 04 июл. 2026
Источник: redhat
CVSS3: 3.3

Описание

A vulnerability has been found in HdrHistogram up to 2.2.2. This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. Such manipulation of the argument Count leads to state issue. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The existence of this vulnerability is still disputed at present. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.

A flaw was found in HdrHistogram. A local attacker could exploit this vulnerability by manipulating the 'Count' argument within the recordValueWithCount function. This manipulation leads to a state issue, which could impact the integrity of data processing within the affected component.

Отчет

This flaw in HdrHistogram is rated as Low impact. A local attacker could manipulate the 'Count' argument in the recordValueWithCount function, leading to a state issue that affects data integrity. Exploitation requires local access to the system where HdrHistogram is used.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftopenshift-logging/vector-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed/lightspeed-ocp-rag-rhel9Not affected
OpenShift Lightspeedopenshift-lightspeed-tech-preview/lightspeed-rag-tool-rhel9Not affected
OpenShift Service Mesh 3openshift-service-mesh/istio-ztunnel-rhel9Not affected
Red Hat Ansible Automation Platform 2ansible-automation-platform-25/lightspeed-chatbot-rhel8Fix deferred
Red Hat Enterprise Linux 8HdrHistogramFix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-llm-d-inference-scheduler-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-model-registry-job-async-upload-rhel9Not affected
Red Hat OpenShift AI (RHOAI)rhoai/odh-trustyai-service-rhel9Fix deferred
Red Hat OpenShift AI (RHOAI)rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-1284
https://bugzilla.redhat.com/show_bug.cgi?id=2497101HdrHistogram: HdrHistogram: Local state issue via 'Count' argument manipulation

3.3 Low

CVSS3

Связанные уязвимости

CVSS3: 3.3
ubuntu
около 1 месяца назад

A vulnerability has been found in HdrHistogram up to 2.2.2. This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. Such manipulation of the argument Count leads to state issue. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The existence of this vulnerability is still disputed at present. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.

CVSS3: 3.3
nvd
около 1 месяца назад

A vulnerability has been found in HdrHistogram up to 2.2.2. This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. Such manipulation of the argument Count leads to state issue. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The existence of this vulnerability is still disputed at present. This issue is disputed due to the potential lack of crossing of security boundaries and the pre-requisites for a successful attack.

CVSS3: 3.3
debian
около 1 месяца назад

A vulnerability has been found in HdrHistogram up to 2.2.2. This vulne ...

CVSS3: 3.3
github
около 1 месяца назад

A vulnerability has been found in HdrHistogram up to 2.2.2. This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. Such manipulation of the argument Count leads to state issue. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

3.3 Low

CVSS3