Описание
zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations.
A flaw was found in zstd-jni. This vulnerability arises from insufficient bounds checks in direct-ByteBuffer frame-size native methods, which allows attackers to provide negative or overflowing offsets. A remote attacker can exploit this by supplying specially crafted negative offset values, leading to out-of-bounds memory reads. This can result in the termination of the Java Virtual Machine (JVM), causing a Denial of Service (DoS), or the disclosure of sensitive information by extracting arbitrary frame size data from unintended memory locations.
Отчет
An out-of-bounds read flaw was found in zstd-jni. Versions before 1.5.7-14 perform insufficient bounds validation in direct ByteBuffer frame-size native methods. An attacker who can provide crafted input with negative or overflowing offsets may cause the JVM to terminate or disclose data from unintended memory locations.
Меры по смягчению последствий
Update zstd-jni to version 1.5.7-14 or later. If an update is not immediately possible, do not pass attacker-controlled buffers or offsets to the affected frame-size methods. Validate offsets and lengths before invoking zstd-jni native methods.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence/agent-client-rhel9 | Not affected | ||
| OpenShift Developer Tools and Services | jenkins-2-plugins | Not affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Not affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Not affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | zstd-jni | Not affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | zstd-jni | Not affected | ||
| Red Hat build of Apicurio Registry 3 | zstd-jni | Not affected | ||
| Red Hat build of Debezium 3 | zstd-jni | Not affected | ||
| Red Hat build of Quarkus | zstd-jni | Not affected | ||
| Red Hat Ceph Storage 9 | libarrow | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
8.2 High
CVSS3
Связанные уязвимости
(zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three ...)
zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations.
zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three ...
zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations.
EPSS
8.2 High
CVSS3