CVE-2026-14686

Red Hat Security Advisory: Red Hat Hardened Images RPMs bug fix and enhancement update

Beschreibung

Ein Fehler wurde in HdrHistogram gefunden. Diese Schwachstelle betrifft die Funktion `DoubleHistogram.recordValue`, die Teil des Bereichsüberprüfungskomponenten ist. Ein lokaler Angreifer kann diesen Fehler ausnutzen, indem er eine bestimmte Manipulation durchführt, was zu einer falschen Vergleich von Werten führt. Dieses Problem beeinträchtigt hauptsächlich die Datenintegrität.

Metriken

Severity
medium
kein öffentlicher PoC bekannt
4.8
Quelle: nvd-v4
25.3 %
Erhöht — CVE ist relevanter als mindestens 10 % der heute bewerteten CVEs.
0.3 %
Niedrig — Modell schätzt < 1 % Ausnutzungs-Wahrscheinlichkeit.
Veröffentlicht
2026-07-02 15:43 UTC
CWE-697

Weakness-Klassen (CWE)

  • CWE-697Pillar

    Incorrect Comparison

    The product compares two entities in a security-relevant context, but the comparison is incorrect.

    cwe.mitre.org →

Re-Analyse & Statuswechsel

Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.

  1. CVE Modified2026-07-06 15:16 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-14686","role":"CISA Coordinator","options":[{"exploitation":"poc"},{"automatable":"no"},{"technicalIm…
  2. New CVE Received2026-07-05 01:21 UTC· cna@vuldb.com
    • Affected: HdrHistogram
    • Description: A vulnerability was found in HdrHistogram up to 2.2.2. This issue affects the function org.HdrHistogram.DoubleHistogram.recordValue of the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the component Range Check. Performing a manipulation results in incorrect comparison. The attack is only possible with local access. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.
    • CVSS V4.0: AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CVSS V3.1: AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N

Betroffene Betriebssysteme

  • linux

    ubuntu / curlbionic

  • linux

    ubuntu / curlfocal

  • linux

    ubuntu / curlnoble

  • linux

    ubuntu / curlquesting

  • linux

    ubuntu / curlresolute

  • linux

    ubuntu / curltrusty

  • linux

    ubuntu / curlxenial

Betroffene Produkte

Aus der Hersteller-/CERT-Meldung extrahierte Produkte und Versionsbereiche. Ein Version-Range wie „<4.14.6“ impliziert die Update-Empfehlung „auf 4.14.6 oder höher aktualisieren“.

  • haxx

    curl7.30.0 – 8.21.0

  • haxx

    curl7.46.0 – 8.20.0

  • haxx

    curl7.46.0 – 8.21.0

  • haxx

    curl7.69.0 – 8.21.0

  • haxx

    curl8.11.1 – 8.21.0

  • haxx

    curl8.13.0 – 8.21.0

  • haxx

    curl8.15.0 – 8.21.0

  • haxx

    curl8.18.0 – 8.21.0

  • Hitachi Energy

    RTU500< 13.9.1

    gefixt in 13.9.1

  • IBM

    App Connect Enterprise< 12.0.12.28

    gefixt in 12.0.12.28

  • IBM

    App Connect Enterprise< 13.0.8.1

    gefixt in 13.0.8.1

  • IBM

    App Connect Enterprise< 13.0.8.2

    gefixt in 13.0.8.2

Quellen & Referenzen

Verknüpfte CVEs

IDCVE-2026-14686