CVE-2025-14549Out-of-bounds Read in OMR

CWE-125Out-of-bounds Read3 documents3 sources
Severity
6.9MEDIUMNVD
EPSS
0.1%
top 77.17%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedDec 15

Description

In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR on Z processors incorrectly handles NUL (0x00) characters during the Latin-compatible charset (UTF-8, ISO8859-1, ASCII, etc) to IBM-1047/037 translation sequence. This can cause the output byte array to be truncated, discarding the first NUL byte and all subsequent characters, and thereby exposing a possible buffer over-read problem. This issue is fixed in Eclipse OMR version 0

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L

Affected Packages2 packages

NVDeclipse/omr0.7.0
CVEListV5eclipse_omr/eclipse_omr0.7.0

Patches

🔴Vulnerability Details

2
CVEList
OMR on Z processors Exposing a possible buffer over-read problem2025-12-15
GHSA
GHSA-rw8m-hvvr-gqpp: In the Eclipse OMR compiler component, since release 02025-12-15
CVE-2025-14549 — Out-of-bounds Read in Eclipse OMR | cvebase