Bug 2497101 (CVE-2026-14685) - CVE-2026-14685 HdrHistogram: HdrHistogram: Local state issue via 'Count' argument manipulation
Summary: CVE-2026-14685 HdrHistogram: HdrHistogram: Local state issue via 'Count' argu...
Keywords:
Status: NEW
Alias: CVE-2026-14685
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
low
low
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2499340
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-05 00:01 UTC by OSIDB Bzimport
Modified: 2026-08-15 08:27 UTC (History)
20 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-05 00:01:37 UTC
A vulnerability has been found in HdrHistogram up to 2.2.2. This vulnerability affects the function recordValueWithCount of the file src/main/java/org/HdrHistogram/AbstractHistogram.java of the component AbstractHistogram. Such manipulation of the argument Count leads to state issue. The attack can only be performed from a local environment. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet.

Comment 3 Florencio Cano 2026-07-11 10:51:42 UTC
AI BU triage note: The upstream HdrHistogram project closed the referenced GitHub issue (https://github.com/HdrHistogram/HdrHistogram/issues/221) as 'BOGUS/SPAM FAKE CVE Report'. NVD status is 'Deferred'. Red Hat CVSS is 3.3/LOW. Pre-existing OSIDB affects on odh-model-registry-job-async-upload-rhel9 and odh-llm-d-inference-scheduler-rhel9 were set to NOTAFFECTED (Vulnerable Code not Present): those images ship the Rust hdrhistogram crate (7.5.4), which is a separate implementation unaffected by this Java-specific flaw (AbstractHistogram.java). New AFFECTED/DEFER affects were created for odh-trustyai-service-rhel9 and odh-workbench-jupyter-trustyai-cpu-py312-rhel9 across rhoai-2.25, rhoai-3.3, rhoai-3.4, which ship org.hdrhistogram/HdrHistogram 2.1.12 (Maven, in range per CVE reporter's claim of '2.2.2 and earlier'). No trackers filed (LOW/DEFER).


Note You need to log in before you can comment on or make changes to this bug.