Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-12183

Опубликовано: 28 нояб. 2025
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

A flaw was found in lz4-java. This vulnerability allows remote attackers to cause denial of service (DoS) and read adjacent memory via untrusted compressed input. This vulnerability affects only programs using the unsafe LZ4_decompress_fast API, known as the "fast" decompressor.

Отчет

This vulnerability affects the "fast" decompressor, this is due to the fact such implementation relies on LZ4_decompress_fast API of the lz4 C library. This function was deprecated in the lz4 library as it misses boundary checks and is considered insecure when processing untrusted inputs. Red Hat has considered this vulnerability as having a security impact of Moderate as the attack may be considered of a high complexity, additionally when exploited the attacker doesn't have full control over the memory read and its content.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4lz4-javaFix deferred
Logging Subsystem for Red Hat OpenShiftlz4-javaFix deferred
Red Hat AMQ Clientslz4-javaFix deferred
Red Hat build of Apache Camel 4 for Quarkus 3lz4-javaFix deferred
Red Hat build of Apache Camel for Spring Boot 4lz4-javaFix deferred
Red Hat build of Apache Camel - HawtIO 4lz4-javaFix deferred
Red Hat build of Apicurio Registry 2lz4-javaFix deferred
Red Hat build of Apicurio Registry 3lz4-javaFix deferred
Red Hat build of Debezium 2lz4-javaFix deferred
Red Hat build of Debezium 3lz4-javaFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2417718lz4-java: lz4-java: Out-of-bounds memory operations lead to denial of service and information disclosure

EPSS

Процентиль: 51%
0.00707
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
9 месяцев назад

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

nvd
9 месяцев назад

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

debian
9 месяцев назад

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier ...

github
9 месяцев назад

LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS

CVSS3: 9.1
fstec
9 месяцев назад

Уязвимость функции LZ4_decompress_fast() библиотеки для сжатия данных lz4-java, позволяющая нарушителю вызвать отказ в обслуживании и раскрыть защищаемую информацию

EPSS

Процентиль: 51%
0.00707
Низкий

6.5 Medium

CVSS3