CVE Vulnerabilities

CVE-2025-52999

Stack-based Buffer Overflow

Published: Jun 25, 2025 | Modified: Jun 26, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
7.5 IMPORTANT
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

jackson-core contains core low-level incremental (streaming) parser and generator abstractions used by Jackson Data Processor. In versions prior to 2.15.0, if a user parses an input file and it has deeply nested data, Jackson could end up throwing a StackoverflowError if the depth is particularly large. jackson-core 2.15.0 contains a configurable limit for how deep Jackson will traverse in an input document, defaulting to an allowable depth of 1000. jackson-core will throw a StreamConstraintsException if the limit is reached. jackson-databind also benefits from this change because it uses jackson-core to parse JSON inputs. As a workaround, users should avoid parsing input files from untrusted sources.

Weakness

A stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).

Affected Software

NameVendorStart VersionEnd Version
OCP-Tools-4.12-RHEL-8RedHatjenkins-0:2.504.2.1750932984-3.el8*
OCP-Tools-4.12-RHEL-8RedHatjenkins-2-plugins-0:4.12.1750933270-1.el8*
OCP-Tools-4.13-RHEL-8RedHatjenkins-0:2.504.2.1750916374-3.el8*
OCP-Tools-4.13-RHEL-8RedHatjenkins-2-plugins-0:4.13.1750916671-1.el8*
OCP-Tools-4.14-RHEL-8RedHatjenkins-0:2.504.2.1750903189-3.el8*
OCP-Tools-4.14-RHEL-8RedHatjenkins-2-plugins-0:4.14.1750903529-1.el8*
OCP-Tools-4.15-RHEL-8RedHatjenkins-0:2.504.2.1750856366-3.el8*
OCP-Tools-4.15-RHEL-8RedHatjenkins-2-plugins-0:4.15.1750856638-1.el8*
OCP-Tools-4.16-RHEL-9RedHatjenkins-0:2.504.2.1750857144-3.el9*
OCP-Tools-4.16-RHEL-9RedHatjenkins-2-plugins-0:4.16.1750857315-1.el9*
OCP-Tools-4.17-RHEL-9RedHatjenkins-0:2.504.2.1750851690-3.el9*
OCP-Tools-4.17-RHEL-9RedHatjenkins-2-plugins-0:4.17.1750851950-1.el9*
OCP-Tools-4.18-RHEL-9RedHatjenkins-0:2.504.2.1750846524-3.el9*
OCP-Tools-4.18-RHEL-9RedHatjenkins-2-plugins-0:4.18.1750846854-1.el9*
Red Hat Enterprise Linux 8RedHatpki-deps:10.6-8100020250731151637.489197e6*
Red Hat Enterprise Linux 8.2 Advanced Update SupportRedHatpki-deps:10.6-8020020250815231424.4cda2c84*
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportRedHatpki-deps:10.6-8040020250815231101.522a0ee4*
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnRedHatpki-deps:10.6-8040020250815231101.522a0ee4*
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportRedHatpki-deps:10.6-8060020250815230318.ad008a3a*
Red Hat Enterprise Linux 8.6 Telecommunications Update ServiceRedHatpki-deps:10.6-8060020250815230318.ad008a3a*
Red Hat Enterprise Linux 8.6 Update Services for SAP SolutionsRedHatpki-deps:10.6-8060020250815230318.ad008a3a*
Red Hat Enterprise Linux 8.8 Telecommunications Update ServiceRedHatpki-deps:10.6-8080020250815110412.63b34585*
Red Hat Enterprise Linux 8.8 Update Services for SAP SolutionsRedHatpki-deps:10.6-8080020250815110412.63b34585*
Red Hat Enterprise Linux 9RedHatjackson-annotations-0:2.19.1-1.el9_6*
Red Hat Enterprise Linux 9RedHatjackson-core-0:2.19.1-1.el9_6*
Red Hat Enterprise Linux 9RedHatjackson-databind-0:2.19.1-1.el9_6*
Red Hat Enterprise Linux 9RedHatjackson-jaxrs-providers-0:2.19.1-1.el9_6*
Red Hat Enterprise Linux 9RedHatjackson-modules-base-0:2.19.1-1.el9_6*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatjackson-annotations-0:2.19.1-1.el9_0*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatjackson-core-0:2.19.1-1.el9_0*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatjackson-databind-0:2.19.1-1.el9_0*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatjackson-jaxrs-providers-0:2.19.1-1.el9_0*
Red Hat Enterprise Linux 9.0 Update Services for SAP SolutionsRedHatjackson-modules-base-0:2.19.1-1.el9_0*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatjackson-annotations-0:2.19.1-1.el9_2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatjackson-core-0:2.19.1-1.el9_2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatjackson-databind-0:2.19.1-1.el9_2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatjackson-jaxrs-providers-0:2.19.1-1.el9_2*
Red Hat Enterprise Linux 9.2 Update Services for SAP SolutionsRedHatjackson-modules-base-0:2.19.1-1.el9_2*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatjackson-annotations-0:2.19.1-1.el9_4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatjackson-core-0:2.19.1-1.el9_4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatjackson-databind-0:2.19.1-1.el9_4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatjackson-jaxrs-providers-0:2.19.1-1.el9_4*
Red Hat Enterprise Linux 9.4 Extended Update SupportRedHatjackson-modules-base-0:2.19.1-1.el9_4*
Red Hat JBoss Enterprise Application Platform 7RedHatjackson-core*
Red Hat JBoss Enterprise Application Platform 7RedHatjackson-core*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-jackson-annotations-0:2.8.11-2.redhat_00004.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-jackson-core-0:2.8.11-3.redhat_00004.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-jackson-jaxrs-providers-0:2.8.11-3.redhat_00004.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-jackson-module-jaxb-annotations-0:2.8.11-3.redhat_00004.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-jackson-modules-java8-0:2.8.11-2.redhat_00004.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-netty-0:4.1.63-3.Final_redhat_00004.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-undertow-0:1.4.18-18.SP16_redhat_00001.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.1 EUS for RHEL 7RedHateap7-wildfly-0:7.1.13-6.GA_redhat_00002.1.ep7.el7*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-annotations-0:2.10.4-4.redhat_00008.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-core-0:2.10.4-4.redhat_00008.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-databind-0:2.10.4-6.redhat_00008.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-jaxrs-providers-0:2.10.4-4.redhat_00008.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-modules-base-0:2.10.4-6.redhat_00008.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jackson-modules-java8-0:2.10.4-3.redhat_00008.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-jboss-server-migration-0:1.7.2-20.Final_redhat_00021.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-netty-0:4.1.63-6.Final_redhat_00004.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-undertow-0:2.0.41-6.SP7_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.3 EUS for RHEL 7RedHateap7-wildfly-0:7.3.16-3.GA_redhat_00003.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jackson-annotations-0:2.12.7-2.redhat_00004.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jackson-core-0:2.12.7-2.SP1_redhat_00001.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jackson-databind-0:2.12.7-2.redhat_00004.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jackson-jaxrs-providers-0:2.12.7-2.redhat_00004.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jackson-modules-base-0:2.12.7-2.redhat_00004.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-jackson-modules-java8-0:2.12.7-2.redhat_00004.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 8RedHateap7-wildfly-0:7.4.23-4.GA_redhat_00003.1.el8eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jackson-annotations-0:2.12.7-2.redhat_00004.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jackson-core-0:2.12.7-2.SP1_redhat_00001.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jackson-databind-0:2.12.7-2.redhat_00004.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jackson-jaxrs-providers-0:2.12.7-2.redhat_00004.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jackson-modules-base-0:2.12.7-2.redhat_00004.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-jackson-modules-java8-0:2.12.7-2.redhat_00004.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 for RHEL 9RedHateap7-wildfly-0:7.4.23-4.GA_redhat_00003.1.el9eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-jackson-annotations-0:2.12.7-2.redhat_00004.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-jackson-core-0:2.12.7-2.SP1_redhat_00001.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-jackson-databind-0:2.12.7-2.redhat_00004.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-jackson-jaxrs-providers-0:2.12.7-2.redhat_00004.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-jackson-modules-base-0:2.12.7-2.redhat_00004.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-jackson-modules-java8-0:2.12.7-2.redhat_00004.1.el7eap*
Red Hat JBoss Enterprise Application Platform 7.4 on RHEL 7RedHateap7-wildfly-0:7.4.23-4.GA_redhat_00003.1.el7eap*
Red Hat Single Sign-On 7.6.12RedHatjackson-core*
Logging for Red Hat OpenShift 5.8RedHatopenshift-logging/elasticsearch6-rhel9:sha256:128a6711150854305d7042e827d191cb5f136fa9591c2410279d9dc0f2b85a75*
Red Hat OpenShift Dev Spaces (RHOSDS) 3.23RedHatdevspaces/server-rhel9:sha256:641354f1d56627f49af3e32ad963616b69aac644ac33d664e7fe29de32fe43b3*
Jackson-coreUbuntuoracular*
Jackson-coreUbuntuplucky*

Potential Mitigations

  • Use automatic buffer overflow detection mechanisms that are offered by certain compilers or compiler extensions. Examples include: the Microsoft Visual Studio /GS flag, Fedora/Red Hat FORTIFY_SOURCE GCC flag, StackGuard, and ProPolice, which provide various mechanisms including canary-based detection and range/index checking.
  • D3-SFCV (Stack Frame Canary Validation) from D3FEND [REF-1334] discusses canary-based detection in detail.
  • Run or compile the software using features or extensions that randomly arrange the positions of a program’s executable and libraries in memory. Because this makes the addresses unpredictable, it can prevent an attacker from reliably jumping to exploitable code.
  • Examples include Address Space Layout Randomization (ASLR) [REF-58] [REF-60] and Position-Independent Executables (PIE) [REF-64]. Imported modules may be similarly realigned if their default memory addresses conflict with other modules, in a process known as “rebasing” (for Windows) and “prelinking” (for Linux) [REF-1332] using randomly generated addresses. ASLR for libraries cannot be used in conjunction with prelink since it would require relocating the libraries at run-time, defeating the whole purpose of prelinking.
  • For more information on these techniques see D3-SAOR (Segment Address Offset Randomization) from D3FEND [REF-1335].

References