Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-87823

Опубликовано: 09 сент. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations.

A flaw was found in zstd-jni. This vulnerability arises from insufficient bounds checks in direct-ByteBuffer frame-size native methods, which allows attackers to provide negative or overflowing offsets. A remote attacker can exploit this by supplying specially crafted negative offset values, leading to out-of-bounds memory reads. This can result in the termination of the Java Virtual Machine (JVM), causing a Denial of Service (DoS), or the disclosure of sensitive information by extracting arbitrary frame size data from unintended memory locations.

Отчет

An out-of-bounds read flaw was found in zstd-jni. Versions before 1.5.7-14 perform insufficient bounds validation in direct ByteBuffer frame-size native methods. An attacker who can provide crafted input with negative or overflowing offsets may cause the JVM to terminate or disclose data from unintended memory locations.

Меры по смягчению последствий

Update zstd-jni to version 1.5.7-14 or later. If an update is not immediately possible, do not pass attacker-controlled buffers or offsets to the affected frame-size methods. Validate offsets and lengths before invoking zstd-jni native methods.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence/agent-client-rhel9Not affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsNot affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Not affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Not affected
Red Hat build of Apache Camel 4 for Quarkus 3zstd-jniNot affected
Red Hat build of Apache Camel for Spring Boot 4zstd-jniNot affected
Red Hat build of Apicurio Registry 3zstd-jniNot affected
Red Hat build of Debezium 3zstd-jniNot affected
Red Hat build of Quarkuszstd-jniNot affected
Red Hat Ceph Storage 9libarrowFix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2531004com.github.luben/zstd-jni: zstd-jni: Denial of Service or Information Disclosure via out-of-bounds read

EPSS

Процентиль: 37%
0.00432
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
6 дней назад

(zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three ...)

CVSS3: 8.2
nvd
6 дней назад

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations.

CVSS3: 8.2
debian
6 дней назад

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three ...

CVSS3: 8.2
github
6 дней назад

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations.

EPSS

Процентиль: 37%
0.00432
Низкий

8.2 High

CVSS3