CVE-2025-50106
The original fix for CVE-2025-30749 was found to be incomplete. In particular, the CGGlyphImages_GetGlyphImagePtrs method incorrectly calculates pointers to the arrays inside the pre-allocated buffer. It caused out-of-memory access and crash.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-50106?
CVE-2025-50106 is a high severity vulnerability affecting multiple versions of Oracle Java SE and GraalVM products.
How do I fix CVE-2025-50106?
To fix CVE-2025-50106, update your Oracle Java SE or GraalVM to the latest patched version available.
Which versions are affected by CVE-2025-50106?
CVE-2025-50106 affects Oracle Java SE versions 8u451, 11.0.27, 17.0.15, 21.0.7, and 24.0.1, as well as certain versions of GraalVM.
Is CVE-2025-50106 exploitable remotely?
Yes, CVE-2025-50106 is potentially exploitable remotely, making it critical to patch affected systems promptly.
What components are impacted by CVE-2025-50106?
CVE-2025-50106 specifically impacts the 2D component of Oracle Java SE and associated GraalVM products.