Bug 2497101 (CVE-2026-14685)

Summary: CVE-2026-14685 HdrHistogram: HdrHistogram: Local state issue via 'Count' argument manipulation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: anpicker, dschmidt, hasun, jcantril, jfula, jlanda, jowilson, kshier, nyancey, ometelka, ptisnovs, rhel-process-autobot, rojacob, simaishi, stcannon, syedriko, teagle, watson-tool-maintainers, xdharmai, yguenane
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in HdrHistogram. A local attacker could exploit this vulnerability by manipulating the 'Count' argument within the `recordValueWithCount` function. This manipulation leads to a state issue, which could impact the integrity of data processing within the affected component.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2499340    
Bug Blocks:    

Description OSIDB Bzimport 2026-07-05 00:01:37 UTC
A vulnerability has been found in HdrHistogram up to 2.2.2. This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. Such manipulation of the argument Count leads to state issue. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Comment 3 Florencio Cano 2026-07-11 10:51:42 UTC
AI BU triage note: The upstream HdrHistogram project closed the referenced GitHub issue (https://github.com/HdrHistogram/HdrHistogram/issues/221) as 'BOGUS/SPAM FAKE CVE Report'. NVD status is 'Deferred'. Red Hat CVSS is 3.3/LOW. Pre-existing OSIDB affects on odh-model-registry-job-async-upload-rhel9 and odh-llm-d-inference-scheduler-rhel9 were set to NOTAFFECTED (Vulnerable Code not Present): those images ship the Rust hdrhistogram crate (7.5.4), which is a separate implementation unaffected by this Java-specific flaw (AbstractHistogram.java). New AFFECTED/DEFER affects were created for odh-trustyai-service-rhel9 and odh-workbench-jupyter-trustyai-cpu-py312-rhel9 across rhoai-2.25, rhoai-3.3, rhoai-3.4, which ship org.hdrhistogram/HdrHistogram 2.1.12 (Maven, in range per CVE reporter's claim of '2.2.2 and earlier'). No trackers filed (LOW/DEFER).