Impact
An integer overflow exists in the tensor buffer validation component of Amazon Deep Java Library. When a malicious actor supplies a malformed tensor payload, the overflow can lead to reading data from adjacent process memory, exposing potentially sensitive information, and it can also trigger a crash, resulting in a denial of service. The flaw is an instance of CWE-190, Integer Overflow or Wraparound, affecting the library's ability to correctly bound internal buffer sizes.
Affected Systems
Amazon Deep Java Library community releases from version 0.13.0 through 0.36.0 on all supported platforms are affected by this vulnerability.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, suggesting that active exploitation is currently unclear. However, a remote unauthenticated attacker can send a crafted tensor payload to any DJL-enabled application, potentially retrieving information from adjacent memory or causing a denial of service. required, making the risk significant for deployments that expose DJL functionality over a network.
OpenCVE Enrichment