Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-87824

Опубликовано: 09 сент. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.

EPSS

Процентиль: 32%
0.00389
Низкий

7.5 High

CVSS3

Дефекты

CWE-125

Связанные уязвимости

CVSS3: 7.5
ubuntu
6 дней назад

(zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity ...)

CVSS3: 7.5
redhat
7 дней назад

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.

CVSS3: 7.5
debian
7 дней назад

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity ...

CVSS3: 7.5
github
7 дней назад

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.

CVSS3: 7.5
fstec
около 1 месяца назад

Уязвимость функции Zstd.trainFromBufferDirect() библиотеки сжатия данных zstd-jni, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 32%
0.00389
Низкий

7.5 High

CVSS3

Дефекты

CWE-125