Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-87824

Опубликовано: 09 сент. 2026
Источник: redhat
CVSS3: 7.5

Описание

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.

A flaw was found in zstd-jni. Attackers can exploit this by supplying oversized per-sample lengths to the Zstd.trainFromBufferDirect function, which fails to validate the samples buffer capacity. This allows for reading past buffer boundaries, leading to out-of-bounds memory access and ultimately causing the Java Virtual Machine (JVM) to terminate, resulting in a Denial of Service (DoS).

Отчет

Red Hat has determined that CVE-2026-87824 affects Red Hat products that include the zstd-jni library in a vulnerable version. The vulnerability can allow a remote attacker to terminate the Java Virtual Machine by supplying crafted sample lengths to the dictionary-training function.

Меры по смягчению последствий

No complete workaround is currently available. As a temporary measure, applications using Zstd.trainFromBufferDirect() should validate that all sample lengths are non-negative and that their total does not exceed the capacity of the samples buffer before calling the function. Avoid passing attacker-controlled sample length arrays to this function until an update is available. Upgrade to a Red Hat product release containing zstd-jni 1.5.7-14 or later when available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence/agent-client-rhel9Affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Affected
Red Hat build of Apache Camel 4 for Quarkus 3zstd-jniAffected
Red Hat build of Apache Camel for Spring Boot 4zstd-jniAffected
Red Hat build of Apicurio Registry 3zstd-jniAffected
Red Hat build of Debezium 3zstd-jniAffected
Red Hat build of Quarkuszstd-jniAffected
Red Hat Ceph Storage 9libarrowFix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2530998com.github.luben/zstd-jni: zstd-jni: Denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
6 дней назад

(zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity ...)

CVSS3: 7.5
nvd
6 дней назад

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.

CVSS3: 7.5
debian
6 дней назад

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity ...

CVSS3: 7.5
github
6 дней назад

zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.

CVSS3: 7.5
fstec
около 1 месяца назад

Уязвимость функции Zstd.trainFromBufferDirect() библиотеки сжатия данных zstd-jni, позволяющая нарушителю вызвать отказ в обслуживании

7.5 High

CVSS3