- Package:
- src:hdrhistogram
- Source:
- src:hdrhistogram
- Submitter:
- Salvatore Bonaccorso
- Date:
- 2026-07-27 03:35:02 UTC
- Severity:
- normal
- Tags:
Hi, The following vulnerabilities were published for hdrhistogram. The issues itself do not really warrant a RC level, but I noticed that the package is at same old version across several releases and should probably get an update for forky at last? CVE-2026-14683[0]: | A vulnerability was detected in HdrHistogram up to 2.2.2. Affected | by this issue is the function | org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of | the file src/main/java/org/HdrHistogram/AbstractHistogram.java. The | manipulation of the argument lengthOfCompressedContents results in | uncontrolled memory allocation. The attack needs to be approached | locally. The exploit is now public and may be used. It is still | unclear if this vulnerability genuinely exists. This issue is | disputed due to the potential lack of crossing of security | boundaries and the pre-requisites for a successful attack. CVE-2026-14684[1]: | A flaw has been found in HdrHistogram up to 2.2.2. This affects the | function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of | the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This | manipulation of the argument numberOfSignificantValueDigits causes | uncontrolled memory allocation. The attack can only be executed | locally. The exploit has been published and may be used. The actual | existence of this vulnerability is currently in question. This issue | is disputed due to the potential lack of crossing of security | boundaries and the pre-requisites for a successful attack. CVE-2026-14685[2]: | A vulnerability has been found in HdrHistogram up to 2.2.2. This | vulnerability affects the function recordValueWithCount of the file | src/main/java/org/HdrHistogram/AbstractHistogram.java of the | component AbstractHistogram. Such manipulation of the argument Count | leads to state issue. The attack can only be performed from a local | environment. The exploit has been disclosed to the public and may be | used. The existence of this vulnerability is still disputed at | present. This issue is disputed due to the potential lack of | crossing of security boundaries and the pre-requisites for a | successful attack. CVE-2026-14686[3]: | A vulnerability was found in HdrHistogram up to 2.2.2. This issue | affects the function org.HdrHistogram.DoubleHistogram.recordValue of | the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the | component Range Check. Performing a manipulation results in | incorrect comparison. The attack is only possible with local access. | The exploit has been made public and could be used. The presence of | this vulnerability remains uncertain at this time. This issue is | disputed due to the potential lack of crossing of security | boundaries and the pre-requisites for a successful attack. If you fix the vulnerabilities please also make sure to include the CVE (Common Vulnerabilities & Exposures) ids in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-14683 https://www.cve.org/CVERecord?id=CVE-2026-14683 [1] https://security-tracker.debian.org/tracker/CVE-2026-14684 https://www.cve.org/CVERecord?id=CVE-2026-14684 [2] https://security-tracker.debian.org/tracker/CVE-2026-14685 https://www.cve.org/CVERecord?id=CVE-2026-14685 [3] https://security-tracker.debian.org/tracker/CVE-2026-14686 https://www.cve.org/CVERecord?id=CVE-2026-14686 Regards, Salvatore
We believe that the bug you reported is fixed in the latest version of
hdrhistogram, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to 1142286@bugs.debian.org,
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
tony mancill <tmancill@debian.org> (supplier of updated hdrhistogram package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing ftpmaster@ftp-master.debian.org)
Format: 1.8
Date: Sun, 26 Jul 2026 17:50:15 -0700
Source: hdrhistogram
Architecture: source
Version: 2.2.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers <pkg-java-maintainers@lists.alioth.debian.org>
Changed-By: tony mancill <tmancill@debian.org>
Closes: 1142286
Changes:
hdrhistogram (2.2.2-1) unstable; urgency=medium
.
* Team upload
* New upstream version 2.2.2
Addresses CVE-2026-14683 CVE-2026-14684 CVE-2026-14685 CVE-2026-14686
(Closes: #1142286)
* Freshen years in d/copyright
* Bump Standards-Version to 4.7.4
* Update to debhelper-compat 13
Checksums-Sha1:
fccb2e3197d823e645881d80919f952621f7815a 2140 hdrhistogram_2.2.2-1.dsc
98c7cc9754a76a07d1b023343ae4ff5c6855ea82 564696 hdrhistogram_2.2.2.orig.tar.xz
5e3e1e15357ccda2a629a64b7e270791e82e5791 5908 hdrhistogram_2.2.2-1.debian.tar.xz
e09d4a389839f16db4d130f2247f99f7b98ceb12 15316 hdrhistogram_2.2.2-1_arm64.buildinfo
Checksums-Sha256:
2ba4cac8151e3af25daf58866e9084878cf17c6552bf644450c963eaff9c7598 2140 hdrhistogram_2.2.2-1.dsc
b4fa34438d7bd54c1050480ef7ffd5b2a00094078fcac529c81188cfd9c1a1f7 564696 hdrhistogram_2.2.2.orig.tar.xz
159c60ca077c090b62805a74fbb40e8a19f71ee0a61ad7e4665c5ac77d19a2f6 5908 hdrhistogram_2.2.2-1.debian.tar.xz
59dcc2a48c3fe81a044cdddee6f263d7c7f7169b5ef2496264c64b2aa95feeb7 15316 hdrhistogram_2.2.2-1_arm64.buildinfo
Files:
cd6e5109bd41c7c955487e6f6ba70037 2140 java optional hdrhistogram_2.2.2-1.dsc
276c94fbe702b410cd79950e96c23a97 564696 java optional hdrhistogram_2.2.2.orig.tar.xz
cf6c8d6c80e0e91d660cd0e4e338a757 5908 java optional hdrhistogram_2.2.2-1.debian.tar.xz
04e54f8a9a54fa2bda844319ada97d0e 15316 java optional hdrhistogram_2.2.2-1_arm64.buildinfo
-----BEGIN PGP SIGNATURE-----
iQJIBAEBCgAyFiEE5Qr9Va3SequXFjqLIdIFiZdLPpYFAmpmzoUUHHRtYW5jaWxs
QGRlYmlhbi5vcmcACgkQIdIFiZdLPpbxqRAA2YPfrNeVNQlak8QdimVlYFkg41Ph
meORNjPRm71uZil2NSfHPccG5LV20nqEJFrHNYCQ3NIFVyAHhZyo2EMVXh5TgL/R
IupwMffdd6Upn+ygJaEBAk4u3U0ATdEtJtODPfg69lauN0sFXZReW2EkhdjC9Cel
4Gg5tZE/+mxkZruT33cvjpwzTJgK6G1Zpx1tYp4IaP8d27SbR23ArsfaTLeZ+Xap
O+TPTs7aZVLMnHLucSZWo0yzRaFDtcTt3JUHA/QpGlClOd2On98gaQS+XGziLqgP
l+KpDrm/yyyaR4zQjnIbkX3RaSWKSK3yxgrj2wYLILffBfeHA/2LKrJlTqjtV0oN
Kh2cpDv4w8gaSy7n1xqZZAYe0E6akTihJ+gmFoXksfGszySCHqpYp2Qmq5StlyjV
YiyFUT7o4E6m3ZWNs96xFOkSNDb1FaUKj8GEqDRF/35kgraHwJX2q3M9l6OHLCVT
/nXPSkDnV/cfQfL4J6ejnAPL6VJ4180lo3iJ9y4W9OF/ibQPnyc6k1K6iWf+stqD
tkEP1eTTvmrK/sxulEbubLsgUeWy7puQlnqz3eHj26uCvCzL/M0/qD0XXGhlVlOm
tukSeoZGHuSa0ynH50no/fKAn66afxsFixKHz4uhjXbDrabULXq22WJ2Y1+JAVg1
7Iu1W9TqleJ5DV8=
=rPiE
-----END PGP SIGNATURE-----