Impact
The vulnerability is located in the Java 2D rendering code of Oracle Java SE. When exploited, the component can produce a hang or crash. The description does not explicitly name the trigger, but based on the mention of font loading it is inferred that malformed font data sent to the 2D APIs causes the failure. The exploit can be performed remotely by an unauthenticated attacker sending crafted data to a network service that invokes the 2D rendering. The effect is a complete denial of service for the Java runtime, with no impact on confidentiality or integrity.
Affected Systems
Oracle Java SE versions 25.0.4 and 26.0.2 are affected. The issue also applies to any Java deployment that relies on the Java 2D APIs, notably sandboxed Java Applet and Java Web Start clients that load code from untrusted sources. The listed CPEs include Red Hat Enterprise Linux 9, Red Hat OpenJDK 25, Hummingbird 1, and Red Hat Enterprise Linux 10.2, indicating that the affected runtime is commonly present on these platforms.
Risk and Exploitability
The CVSS base score is 7.5, classifying this as a high‑severity vulnerability that attacks availability. Because the vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, no privileges or user interaction are needed. The EPSS score is <1%, which signals a low but non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The description indicates that an unauthenticated, network‑based attacker can exploit the flaw, implying a remote attack through services that expose the vulnerable 2D font loading functionality.
OpenCVE Enrichment
Debian DSA