VYPR
High severity8.1OSV Advisory· Published Dec 15, 2025· Updated Jun 17, 2026

CVE-2025-14549

CVE-2025-14549

Description

In the Eclipse OMR compiler component, since release 0.7.0, an optimization enabled for Eclipse OpenJ9 consumers of OMR on Z processors incorrectly handles NUL (0x00) characters during the Latin-compatible charset (UTF-8, ISO8859-1, ASCII, etc) to IBM-1047/037 translation sequence. This can cause the output byte array to be truncated, discarding the first NUL byte and all subsequent characters, and thereby exposing a possible buffer over-read problem. This issue is fixed in Eclipse OMR version 0.8.0.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • Eclipse/OmrOSV3 versions
    omr-0.1.0, omr-0.2.0, omr-0.3.0, …+ 2 more
    • (no CPE)range: omr-0.1.0, omr-0.2.0, omr-0.3.0, …
    • (no CPE)range: >=0.7.0 <0.8.0
    • cpe:2.3:a:eclipse:omr:0.7.0:*:*:*:*:*:*:*

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.