CVE-2026-14683

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Beschreibung

Ein Fehler wurde im HdrHistogram gefunden. Ein lokaler Angreifer kann eine Schwachstelle in der Funktion `decodeFromCompressedByteBuffer` ausnutzen, indem er den Argumentwert `lengthOfCompressedContents` manipuliert. Diese Manipulation führt zu einer unkontrollierten Speicherzuweisung, was zu einem Denial-of-Service (DoS)-Zustand führen kann und das betroffene System unverfügbar macht.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
4.8
Quelle: nvd-v4
5.5 %
Niedrig — CVE gehört zu den unteren 10 % der heute bewerteten CVEs.
0.2 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-02 15:43 UTC
CWE-789, CWE-400

Weakness-Klassen (CWE)

  • CWE-789Variant

    Memory Allocation with Excessive Size Value

    The product allocates memory based on an untrusted, large size value, but it does not ensure that the size is within expected limits, allowing arbitrary amounts of memory to be allocated.

    cwe.mitre.org →
  • CWE-400Class

    Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-07-07 04:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-14683","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalIm…

Betroffene Betriebssysteme

  • linux

    ubuntu / curlbionic

  • linux

    ubuntu / curlfocal

  • linux

    ubuntu / curlnoble

  • linux

    ubuntu / curlquesting

  • linux

    ubuntu / curlresolute

  • linux

    ubuntu / curltrusty

  • linux

    ubuntu / curlxenial

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • haxx

    curl7.30.0 – 8.21.0

  • haxx

    curl7.46.0 – 8.20.0

  • haxx

    curl7.46.0 – 8.21.0

  • haxx

    curl7.69.0 – 8.21.0

  • haxx

    curl8.11.1 – 8.21.0

  • haxx

    curl8.13.0 – 8.21.0

  • haxx

    curl8.15.0 – 8.21.0

  • haxx

    curl8.18.0 – 8.21.0

  • Hitachi Energy

    RTU500< 13.9.1

    gefixt in 13.9.1

  • IBM

    App Connect Enterprise< 12.0.12.28

    gefixt in 12.0.12.28

  • IBM

    App Connect Enterprise< 13.0.8.1

    gefixt in 13.0.8.1

  • IBM

    App Connect Enterprise< 13.0.8.2

    gefixt in 13.0.8.2

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-14683