Incorrect Calculation of Buffer Size Affecting eclipse-omr/omr package, versions [0.2.0,0.8.0)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.49% (39th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-ECLIPSEOMROMR-15146992
  • published29 Jan 2026
  • disclosed29 Jan 2026
  • creditUnknown

Introduced: 29 Jan 2026

CVE-2026-1188  (opens in a new tab)
CWE-131  (opens in a new tab)

How to fix?

Upgrade eclipse-omr/omr to version 0.8.0 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Calculation of Buffer Size in the omrsysinfo_get_processor_feature_string () function. A buffer overflow can happen with incorrect assignment of an output buffer for API response with the textual names of all supported processor that contain separator.

CVSS Base Scores

version 4.0
version 3.1