{"id":"CVE-2025-14549","summary":"OMR on Z processors Exposing a possible buffer over-read problem","details":"In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR on Z processors incorrectly handles NUL (0x00) characters during the Latin-compatible charset (UTF-8, ISO8859-1, ASCII, etc) to IBM-1047/037 translation sequence. This can cause the output byte array to be truncated, discarding the first NUL byte and all subsequent characters, and thereby exposing a possible buffer over-read problem. This issue is fixed in Eclipse OMR version 0.8.0.","modified":"2026-08-12T03:51:42.292508075Z","published":"2025-12-15T05:32:22.095Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14549.json","cna_assigner":"eclipse","cwe_ids":["CWE-125"]},"references":[{"type":"WEB","url":"https://projects.eclipse.org/projects/technology.omr"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/14xxx/CVE-2025-14549.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-14549"},{"type":"FIX","url":"https://github.com/eclipse-omr/omr/pull/8073"},{"type":"PACKAGE","url":"https://github.com/eclipse-omr/omr"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/eclipse-omr/omr","events":[{"introduced":"01268e034df7dd66418b7f2dc4b1d861e9aa91b0"},{"last_affected":"01268e034df7dd66418b7f2dc4b1d861e9aa91b0"}],"database_specific":{"cpe":"cpe:2.3:a:eclipse:omr:0.7.0:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0.7.0"},{"last_affected":"0.7.0"}],"source":["AFFECTED_FIELD","CPE_STRING"]}}],"versions":["0.7.0","omr-0.7.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2025-14549.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L"}]}