In the Eclipse OMR port library component since release 0.2.0, an API function to return the textual names of all supported processor features was not accounting for the separator inserted between processor features. If the output buffer supplied to this function was incorrectly sized, failing to account for the separator when determining when a write to the buffer was safe could lead to a buffer overflow. This issue is fixed in Eclipse OMR version 0.8.0.
CVSS Details
- CVSS 4.0 Base Score: 6.9 (MEDIUM)
- CVSS 4.0 Vector: (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X)
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Ibm Java | — | Upgrade IBM Java to version 8.0.8.55 | Jan 29, 2026 | Jan 29, 2026 |
| Ibm Was | — | Upgrade to minimal fix pack levels as required by interim fixes and then apply latest Interim Fix. | Jan 29, 2026 | Jan 29, 2026 |
| Suse | — | Upgrade java-21-openj9-demoUpgrade java-17-openj9-demoUpgrade java-17-openj9-develUpgrade java-21-openj9-javadocUpgrade java-21-openj9-jmodsUpgrade java-21-openj9-srcUpgrade java-1_8_0-ibm-alsaUpgrade java-1_8_0-ibm-demoUpgrade java-17-openj9-javadocUpgrade java-17-openj9-headlessUpgrade java-17-openj9-srcUpgrade java-17-openj9-jmodsUpgrade java-21-openj9Upgrade java-1_8_0-ibm-develUpgrade java-1_8_0-ibm-pluginUpgrade java-21-openj9-headlessUpgrade java-21-openj9-develUpgrade java-17-openj9Upgrade java-1_8_0-ibm-srcUpgrade java-1_8_0-ibm | Jun 1, 2026 | May 21, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub