Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-87877

Опубликовано: 09 сент. 2026
Источник: redhat
CVSS3: 7.7
EPSS Низкий

Описание

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.

A flaw was found in zstd-jni. An attacker could exploit a use-after-free vulnerability by calling specific methods on closed streams without proper validation. This could lead to memory corruption, potentially allowing the attacker to corrupt unrelated objects or cause the Java Virtual Machine (JVM) to crash, resulting in a denial of service.

Отчет

Red Hat has determined that CVE-2026-87877 affects Red Hat products that include the zstd-jni library in a vulnerable version. The vulnerability can allow memory corruption or denial of service when specific stream methods are called after the stream has been closed.

Меры по смягчению последствий

No complete workaround is currently available. As a temporary measure, applications using zstd-jni should not call setDict(), setLongMax(), setLevel(), or setRefMultipleDDicts() on a stream after close(). Upgrade to a Red Hat product release containing zstd-jni 1.5.7-14 or later when available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence/agent-client-rhel9Affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Affected
Red Hat build of Apache Camel 4 for Quarkus 3zstd-jniAffected
Red Hat build of Apache Camel for Spring Boot 4zstd-jniAffected
Red Hat build of Apicurio Registry 3zstd-jniAffected
Red Hat build of Debezium 3zstd-jniAffected
Red Hat build of Quarkuszstd-jniAffected
Red Hat Ceph Storage 9libarrowFix deferred

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-416
https://bugzilla.redhat.com/show_bug.cgi?id=2531003com.github.luben/zstd-jni: zstd-jni: Use-After-Free vulnerability allows memory corruption and denial of service

EPSS

Процентиль: 10%
0.00201
Низкий

7.7 High

CVSS3

Связанные уязвимости

CVSS3: 7.7
ubuntu
6 дней назад

(zstd-jni versions before 1.5.7-14 fail to validate closed state in set ...)

CVSS3: 7.7
nvd
6 дней назад

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.

CVSS3: 7.7
debian
6 дней назад

zstd-jni versions before 1.5.7-14 fail to validate closed state in set ...

CVSS3: 7.7
github
6 дней назад

zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.

CVSS3: 7.7
fstec
около 1 месяца назад

Уязвимость функций setDict(), setLongMax() и setLevel() библиотеки сжатия данных zstd-jni, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 10%
0.00201
Низкий

7.7 High

CVSS3