Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2026-87795

Опубликовано: 09 сент. 2026
Источник: debian

Описание

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
zstd-jni-javaunfixedpackage

Примечания

  • https://github.com/luben/zstd-jni/security/advisories/GHSA-ff36-7w3w-g8rm

  • Fixed by: https://github.com/luben/zstd-jni/commit/0d64de4dee6606ff506be36c7f2e714ad0c80fdb (v1.5.7-14)

Связанные уязвимости

CVSS3: 8.2
ubuntu
6 дней назад

(zstd-jni versions before 1.5.7-14 fail to validate offset and length p ...)

CVSS3: 8.2
redhat
7 дней назад

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

CVSS3: 8.2
nvd
7 дней назад

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

CVSS3: 8.2
github
7 дней назад

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

CVSS3: 8.2
fstec
около 1 месяца назад

Уязвимость компонента ZstdDictCompress библиотеки сжатия данных zstd-jni, позволяющая нарушителю выполнить произвольный код