Executive brief
LatencyUtils is a Java library for tracking operation latencies and correcting for system pauses (e.g., garbage collection). A flaw in the pause-detection mechanism can cause an uncaught exception in a shared background thread when a detected pause exceeds configured limits. This permanently kills the thread and causes unbounded memory growth from queued events that are never processed, eventually leading to process-wide OutOfMemoryError and silent loss of latency monitoring across all affected components.
Technical details
The vulnerability is an uncaught exception in the shared PauseDetector dispatch thread. When LatencyStats.recordDetectedPause() receives a pause length exceeding highestTrackableLatency, it forwards this out-of-range value to HdrHistogram.recordValueWithExpectedInterval(), which throws an unchecked ArrayIndexOutOfBoundsException. The dispatch thread's run-loop only catches InterruptedException, so the RuntimeException propagates uncaught and kills the thread. Because this is a process-wide static singleton shared by all LatencyStats instances and the work queue is unbounded, the consequences are: (1) unbounded memory growth from queued but unconsumed events leading to OutOfMemoryError; (2) permanent loss of pause-correction telemetry for all LatencyStats in the JVM; and (3) potential deadlock of listener lifecycle operations. Attack requires local access and ability to trigger a system pause exceeding configured thresholds. Patches or workarounds are not yet available as of the advisory date.
Affected products
- LatencyUtils LatencyUtils up to 2.0.3
Timeline
- 2026-08-31: disclosed: Publicly disclosed via GitHub issue #22
- 2026-08-31: advisory: CVE-2026-82596 published