CVE-2026-16243
5.7
CVSS:4.0/AV:N/AC:H/AT:P/PR:L/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:L
Summary
In Eclipse OMR versions up to 0.11, the arraycmp SIMD implementation for Z and P does not check if the number of bytes to compare is zero.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Eclipse Foundation | Eclipse OMR | 0.1 < 0.11 | affected |
| Eclipse Foundation | Eclipse OMR | 0 < 0.1 | unaffected |
| Eclipse Foundation | Eclipse OMR | 0.11 | unaffected |
Weaknesses
- CWE-125: CWE-125 Out-of-bounds read
References
- https://github.com/eclipse-omr/omr/pull/8349
- https://github.com/eclipse-omr/omr/pull/8348
- https://gitlab.eclipse.org/security/cve-assignment/-/work_items/195
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.