Описание
zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.
A flaw was found in zstd-jni. Attackers can exploit this by supplying oversized per-sample lengths to the Zstd.trainFromBufferDirect function, which fails to validate the samples buffer capacity. This allows for reading past buffer boundaries, leading to out-of-bounds memory access and ultimately causing the Java Virtual Machine (JVM) to terminate, resulting in a Denial of Service (DoS).
Отчет
Red Hat has determined that CVE-2026-87824 affects Red Hat products that include the zstd-jni library in a vulnerable version. The vulnerability can allow a remote attacker to terminate the Java Virtual Machine by supplying crafted sample lengths to the dictionary-training function.
Меры по смягчению последствий
No complete workaround is currently available. As a temporary measure, applications using Zstd.trainFromBufferDirect() should validate that all sample lengths are non-negative and that their total does not exceed the capacity of the samples buffer before calling the function. Avoid passing attacker-controlled sample length arrays to this function until an update is available. Upgrade to a Red Hat product release containing zstd-jni 1.5.7-14 or later when available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence/agent-client-rhel9 | Affected | ||
| OpenShift Developer Tools and Services | jenkins-2-plugins | Affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | zstd-jni | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | zstd-jni | Affected | ||
| Red Hat build of Apicurio Registry 3 | zstd-jni | Affected | ||
| Red Hat build of Debezium 3 | zstd-jni | Affected | ||
| Red Hat build of Quarkus | zstd-jni | Affected | ||
| Red Hat Ceph Storage 9 | libarrow | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
7.5 High
CVSS3
Связанные уязвимости
(zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity ...)
zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.
zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity ...
zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.
Уязвимость функции Zstd.trainFromBufferDirect() библиотеки сжатия данных zstd-jni, позволяющая нарушителю вызвать отказ в обслуживании
7.5 High
CVSS3