EIP-2026-102333
PRE-CVEOracle Java Runtime Environment - Heap Out-of-Bounds Read During TTF Font Rendering in OpenTypeLayoutEngine::adjustGlyphPositions
Title source: legacyExploitation Summary
EIP tracks 1 public exploit for EIP-2026-102333. PoCs published by Google Security Research.
AI-analyzed exploit summary This exploit demonstrates a heap-based out-of-bounds read vulnerability in Oracle Java Runtime Environment 8u202, triggered by processing malformed TrueType fonts. The crash occurs in the `OpenTypeLayoutEngine::adjustGlyphPositions` function, leading to a SIGSEGV or access violation on both Linux and Windows platforms.
Description
Oracle Java Runtime Environment - Heap Out-of-Bounds Read During TTF Font Rendering in OpenTypeLayoutEngine::adjustGlyphPositions
Exploits (1)
This exploit demonstrates a heap-based out-of-bounds read vulnerability in Oracle Java Runtime Environment 8u202, triggered by processing malformed TrueType fonts. The crash occurs in the `OpenTypeLayoutEngine::adjustGlyphPositions` function, leading to a SIGSEGV or access violation on both Linux and Windows platforms.