Impact
A buffer over-read occurs in Apache Tomcat Native during the TLS handshake, allowing a crafted request to cause the Java Virtual Machine to crash. This leads to a full denial of service for the affected Tomcat instance until the process is restarted. The flaw is identified as CWE-126, a type of out‑of-bounds read.
Affected Systems
Apache Tomcat Native versions 2.0.0 through 2.0.15 and 1.3.0 through 1.3.8 are impacted; earlier unsupported releases may also be affected. The official fix is available in 2.0.16 and 1.3.9.
Risk and Exploitability
The vulnerability can be triggered by a malicious actor initiating a TLS handshake that contains an improperly crafted record. Based on the description, it is inferred that such an attack can be performed remotely over the network. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog, suggesting that publicly known exploitation may be limited. Nevertheless, remote exploitation would result in a JVM crash and immediate service disruption.
OpenCVE Enrichment