Описание
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes.
A flaw was found in zstd-jni. This use-after-free vulnerability occurs because streams and contexts only hold a dictionary's shared lock during the load call, allowing the dictionary to be closed while still being referenced. A remote attacker could exploit this by closing a dictionary after associating it with a stream or context. Subsequent read or write operations would then access freed native memory, leading to silent data corruption or a Java Virtual Machine (JVM) crash, resulting in a denial of service.
Отчет
This is an Important flaw in zstd-jni that could lead to silent data corruption or JVM crashes due to a use-after-free vulnerability. The flaw arises when a dictionary is prematurely closed while still actively referenced by compression or decompression streams, potentially impacting Red Hat products that utilize zstd-jni for data handling.
Меры по смягчению последствий
Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base, or stability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence/agent-client-rhel9 | Affected | ||
| OpenShift Developer Tools and Services | jenkins-2-plugins | Affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | zstd-jni | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | zstd-jni | Affected | ||
| Red Hat build of Apicurio Registry 3 | zstd-jni | Affected | ||
| Red Hat build of Debezium 3 | zstd-jni | Affected | ||
| Red Hat build of Quarkus | zstd-jni | Affected | ||
| Red Hat Ceph Storage 9 | libarrow | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.7 High
CVSS3
Связанные уязвимости
(zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where ...)
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes.
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where ...
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes.
Уязвимость компонентов ZstdCompressCtx и ZstdDecompressCtx библиотеки сжатия данных zstd-jni, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.7 High
CVSS3