Your message dated Mon, 27 Jul 2026 03:33:39 +0000
with message-id <[email protected]>
and subject line Bug#1142286: fixed in hdrhistogram 2.2.2-1
has caused the Debian Bug report #1142286,
regarding hdrhistogram: CVE-2026-14683 CVE-2026-14684 CVE-2026-14685 
CVE-2026-14686
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1142286: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1142286
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: hdrhistogram
Version: 2.1.11-1
Severity: grave
Tags: security upstream
Justification: user security hole
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for hdrhistogram.

The issues itself do not really warrant a RC level, but I noticed that
the package is at same old version across several releases and should
probably get an update for forky at last?

CVE-2026-14683[0]:
| A vulnerability was detected in HdrHistogram up to 2.2.2. Affected
| by this issue is the function
| org.HdrHistogram.AbstractHistogram.decodeFromCompressedByteBuffer of
| the file src/main/java/org/HdrHistogram/AbstractHistogram.java. The
| manipulation of the argument lengthOfCompressedContents results in
| uncontrolled memory allocation. The attack needs to be approached
| locally. The exploit is now public and may be used. It is still
| unclear if this vulnerability genuinely exists. This issue is
| disputed due to the potential lack of crossing of security
| boundaries and the pre-requisites for a successful attack.


CVE-2026-14684[1]:
| A flaw has been found in HdrHistogram up to 2.2.2. This affects the
| function org.HdrHistogram.AbstractHistogram.decodeFromByteBuffer of
| the file src/main/java/org/HdrHistogram/AbstractHistogram.java. This
| manipulation of the argument numberOfSignificantValueDigits causes
| uncontrolled memory allocation. The attack can only be executed
| locally. The exploit has been published and may be used. The actual
| existence of this vulnerability is currently in question. This issue
| is disputed due to the potential lack of crossing of security
| boundaries and the pre-requisites for a successful attack.


CVE-2026-14685[2]:
| A vulnerability has been found in HdrHistogram up to 2.2.2. This
| vulnerability affects the function recordValueWithCount of the file
| src/main/java/org/HdrHistogram/AbstractHistogram.java of the
| component AbstractHistogram. Such manipulation of the argument Count
| leads to state issue. The attack can only be performed from a local
| environment. The exploit has been disclosed to the public and may be
| used. The existence of this vulnerability is still disputed at
| present. This issue is disputed due to the potential lack of
| crossing of security boundaries and the pre-requisites for a
| successful attack.


CVE-2026-14686[3]:
| A vulnerability was found in HdrHistogram up to 2.2.2. This issue
| affects the function org.HdrHistogram.DoubleHistogram.recordValue of
| the file src/main/java/org/HdrHistogram/DoubleHistogram.java of the
| component Range Check. Performing a manipulation results in
| incorrect comparison. The attack is only possible with local access.
| The exploit has been made public and could be used. The presence of
| this vulnerability remains uncertain at this time. This issue is
| disputed due to the potential lack of crossing of security
| boundaries and the pre-requisites for a successful attack.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-14683
    https://www.cve.org/CVERecord?id=CVE-2026-14683
[1] https://security-tracker.debian.org/tracker/CVE-2026-14684
    https://www.cve.org/CVERecord?id=CVE-2026-14684
[2] https://security-tracker.debian.org/tracker/CVE-2026-14685
    https://www.cve.org/CVERecord?id=CVE-2026-14685
[3] https://security-tracker.debian.org/tracker/CVE-2026-14686
    https://www.cve.org/CVERecord?id=CVE-2026-14686

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: hdrhistogram
Source-Version: 2.2.2-1
Done: tony mancill <[email protected]>

We believe that the bug you reported is fixed in the latest version of
hdrhistogram, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
tony mancill <[email protected]> (supplier of updated hdrhistogram package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 26 Jul 2026 17:50:15 -0700
Source: hdrhistogram
Architecture: source
Version: 2.2.2-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers 
<[email protected]>
Changed-By: tony mancill <[email protected]>
Closes: 1142286
Changes:
 hdrhistogram (2.2.2-1) unstable; urgency=medium
 .
   * Team upload
   * New upstream version 2.2.2
     Addresses CVE-2026-14683 CVE-2026-14684 CVE-2026-14685 CVE-2026-14686
     (Closes: #1142286)
   * Freshen years in d/copyright
   * Bump Standards-Version to 4.7.4
   * Update to debhelper-compat 13
Checksums-Sha1:
 fccb2e3197d823e645881d80919f952621f7815a 2140 hdrhistogram_2.2.2-1.dsc
 98c7cc9754a76a07d1b023343ae4ff5c6855ea82 564696 hdrhistogram_2.2.2.orig.tar.xz
 5e3e1e15357ccda2a629a64b7e270791e82e5791 5908 
hdrhistogram_2.2.2-1.debian.tar.xz
 e09d4a389839f16db4d130f2247f99f7b98ceb12 15316 
hdrhistogram_2.2.2-1_arm64.buildinfo
Checksums-Sha256:
 2ba4cac8151e3af25daf58866e9084878cf17c6552bf644450c963eaff9c7598 2140 
hdrhistogram_2.2.2-1.dsc
 b4fa34438d7bd54c1050480ef7ffd5b2a00094078fcac529c81188cfd9c1a1f7 564696 
hdrhistogram_2.2.2.orig.tar.xz
 159c60ca077c090b62805a74fbb40e8a19f71ee0a61ad7e4665c5ac77d19a2f6 5908 
hdrhistogram_2.2.2-1.debian.tar.xz
 59dcc2a48c3fe81a044cdddee6f263d7c7f7169b5ef2496264c64b2aa95feeb7 15316 
hdrhistogram_2.2.2-1_arm64.buildinfo
Files:
 cd6e5109bd41c7c955487e6f6ba70037 2140 java optional hdrhistogram_2.2.2-1.dsc
 276c94fbe702b410cd79950e96c23a97 564696 java optional 
hdrhistogram_2.2.2.orig.tar.xz
 cf6c8d6c80e0e91d660cd0e4e338a757 5908 java optional 
hdrhistogram_2.2.2-1.debian.tar.xz
 04e54f8a9a54fa2bda844319ada97d0e 15316 java optional 
hdrhistogram_2.2.2-1_arm64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJIBAEBCgAyFiEE5Qr9Va3SequXFjqLIdIFiZdLPpYFAmpmzoUUHHRtYW5jaWxs
QGRlYmlhbi5vcmcACgkQIdIFiZdLPpbxqRAA2YPfrNeVNQlak8QdimVlYFkg41Ph
meORNjPRm71uZil2NSfHPccG5LV20nqEJFrHNYCQ3NIFVyAHhZyo2EMVXh5TgL/R
IupwMffdd6Upn+ygJaEBAk4u3U0ATdEtJtODPfg69lauN0sFXZReW2EkhdjC9Cel
4Gg5tZE/+mxkZruT33cvjpwzTJgK6G1Zpx1tYp4IaP8d27SbR23ArsfaTLeZ+Xap
O+TPTs7aZVLMnHLucSZWo0yzRaFDtcTt3JUHA/QpGlClOd2On98gaQS+XGziLqgP
l+KpDrm/yyyaR4zQjnIbkX3RaSWKSK3yxgrj2wYLILffBfeHA/2LKrJlTqjtV0oN
Kh2cpDv4w8gaSy7n1xqZZAYe0E6akTihJ+gmFoXksfGszySCHqpYp2Qmq5StlyjV
YiyFUT7o4E6m3ZWNs96xFOkSNDb1FaUKj8GEqDRF/35kgraHwJX2q3M9l6OHLCVT
/nXPSkDnV/cfQfL4J6ejnAPL6VJ4180lo3iJ9y4W9OF/ibQPnyc6k1K6iWf+stqD
tkEP1eTTvmrK/sxulEbubLsgUeWy7puQlnqz3eHj26uCvCzL/M0/qD0XXGhlVlOm
tukSeoZGHuSa0ynH50no/fKAn66afxsFixKHz4uhjXbDrabULXq22WJ2Y1+JAVg1
7Iu1W9TqleJ5DV8=
=rPiE
-----END PGP SIGNATURE-----

Attachment: pgp5g67tw2zC0.pgp
Description: PGP signature


--- End Message ---

Reply via email to