Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2025-66566

Опубликовано: 05 дек. 2025
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where the output buffer is reused without being cleared, this may lead to disclosure of sensitive data. JNI-based implementations are not affected. This vulnerability is fixed in 1.10.1.

A flaw was found in lz4-java. This vulnerability allows disclosure of sensitive data via crafted compressed input due to insufficient clearing of the output buffer in Java-based decompressor implementations.

Отчет

This vulnerability is rated IMPORTANT because it allows for information disclosure when Java-based decompressor implementations reuse output buffers without proper clearing, potentially exposing sensitive data via crafted compressed input. JNI-based implementations of lz4-java are not affected by this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Logging Subsystem for Red Hat OpenShiftlz4-javaWill not fix
Red Hat build of Apache Camel 4 for Quarkus 3lz4-javaAffected
Red Hat build of Apache Camel - HawtIO 4lz4-javaNot affected
Red Hat build of Apicurio Registry 2lz4-javaAffected
Red Hat build of Apicurio Registry 3lz4-javaAffected
Red Hat build of Debezium 2lz4-javaWill not fix
Red Hat build of Debezium 3lz4-javaWill not fix
Red Hat Data Grid 8lz4-javaNot affected
Red Hat Enterprise Linux 8jmc:rhel8/lz4-javaAffected
Red Hat Fuse 7lz4-javaWill not fix

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-908
https://bugzilla.redhat.com/show_bug.cgi?id=2419500lz4-java: lz4-java: Information Disclosure via Insufficient Output Buffer Clearing

EPSS

Процентиль: 21%
0.00068
Низкий

7.5 High

CVSS3

Связанные уязвимости

ubuntu
4 месяца назад

yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where the output buffer is reused without being cleared, this may lead to disclosure of sensitive data. JNI-based implementations are not affected. This vulnerability is fixed in 1.10.1.

nvd
4 месяца назад

yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via crafted compressed input. In applications where the output buffer is reused without being cleared, this may lead to disclosure of sensitive data. JNI-based implementations are not affected. This vulnerability is fixed in 1.10.1.

debian
4 месяца назад

yawkat LZ4 Java provides LZ4 compression for Java. Insufficient cleari ...

github
4 месяца назад

yawkat LZ4 Java has a possible information leak in Java safe decompressor

oracle-oval
3 месяца назад

ELSA-2026-0752: jmc security update (IMPORTANT)

EPSS

Процентиль: 21%
0.00068
Низкий

7.5 High

CVSS3

Уязвимость CVE-2025-66566