Описание
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
A flaw was found in lz4-java. This vulnerability allows remote attackers to cause denial of service (DoS) and read adjacent memory via untrusted compressed input. This vulnerability affects only programs using the unsafe LZ4_decompress_fast API, known as the "fast" decompressor.
Отчет
This vulnerability affects the "fast" decompressor, this is due to the fact such implementation relies on LZ4_decompress_fast API of the lz4 C library. This function was deprecated in the lz4 library as it misses boundary checks and is considered insecure when processing untrusted inputs. Red Hat has considered this vulnerability as having a security impact of Moderate as the attack may be considered of a high complexity, additionally when exploited the attacker doesn't have full control over the memory read and its content.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Cryostat 4 | lz4-java | Fix deferred | ||
| Logging Subsystem for Red Hat OpenShift | lz4-java | Fix deferred | ||
| Red Hat AMQ Clients | lz4-java | Fix deferred | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | lz4-java | Fix deferred | ||
| Red Hat build of Apache Camel for Spring Boot 4 | lz4-java | Fix deferred | ||
| Red Hat build of Apache Camel - HawtIO 4 | lz4-java | Fix deferred | ||
| Red Hat build of Apicurio Registry 2 | lz4-java | Fix deferred | ||
| Red Hat build of Apicurio Registry 3 | lz4-java | Fix deferred | ||
| Red Hat build of Debezium 2 | lz4-java | Fix deferred | ||
| Red Hat build of Debezium 3 | lz4-java | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier ...
LZ4 Java Compression has Out-of-bounds memory operations which can cause DoS
Уязвимость функции LZ4_decompress_fast() библиотеки для сжатия данных lz4-java, позволяющая нарушителю вызвать отказ в обслуживании и раскрыть защищаемую информацию
EPSS
6.5 Medium
CVSS3