CVE-2026-82596
Description
A flaw was found in LatencyUtils. A local attacker can exploit this vulnerability by performing a manipulation within the PauseDetector component, specifically affecting the LatencyStats.recordDetectedPause function. This can lead to memory corruption, potentially impacting the stability and integrity of the system.
Statement
A flaw was found in LatencyUtils where an uncaught exception in the PauseDetector component can permanently disable pause tracking across the entire JVM process. When a detected pause exceeds the configured threshold, an ArrayIndexOutOfBoundsException is thrown but not caught, killing the shared background thread. This causes an unbounded queue to grow indefinitely, eventually leading to memory exhaustion. The vulnerability requires either environmental conditions (very long GC pauses, VM suspends) or misconfigured low thresholds to trigger.
Mitigation
Avoid setting very low `highestTrackableLatency` values in LatencyUtils configuration. Monitor for thread death in pause detection and implement application-level monitoring to detect unbounded queue growth. Update to a patched version when available.
Understanding the Weakness (CWE)
Availability
Technical Impact: DoS: Resource Consumption (CPU); DoS: Resource Consumption (Memory); DoS: Resource Consumption (Other)
When allocating resources without limits, an attacker could prevent other systems, applications, or processes from accessing the same type of resource. It can be easy for an attacker to consume many resources by rapidly making many requests or causing larger resources to be used than is needed.
Frequently Asked Questions
Not sure what something means? Check out our Security Glossary.
Want to get errata notifications? Sign up here.