Описание
zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.
A flaw was found in zstd-jni. An attacker could exploit a use-after-free vulnerability by calling specific methods on closed streams without proper validation. This could lead to memory corruption, potentially allowing the attacker to corrupt unrelated objects or cause the Java Virtual Machine (JVM) to crash, resulting in a denial of service.
Отчет
Red Hat has determined that CVE-2026-87877 affects Red Hat products that include the zstd-jni library in a vulnerable version. The vulnerability can allow memory corruption or denial of service when specific stream methods are called after the stream has been closed.
Меры по смягчению последствий
No complete workaround is currently available. As a temporary measure, applications using zstd-jni should not call setDict(), setLongMax(), setLevel(), or setRefMultipleDDicts() on a stream after close(). Upgrade to a Red Hat product release containing zstd-jni 1.5.7-14 or later when available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence/agent-client-rhel9 | Affected | ||
| OpenShift Developer Tools and Services | jenkins-2-plugins | Affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | zstd-jni | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | zstd-jni | Affected | ||
| Red Hat build of Apicurio Registry 3 | zstd-jni | Affected | ||
| Red Hat build of Debezium 3 | zstd-jni | Affected | ||
| Red Hat build of Quarkus | zstd-jni | Affected | ||
| Red Hat Ceph Storage 9 | libarrow | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
7.7 High
CVSS3
Связанные уязвимости
(zstd-jni versions before 1.5.7-14 fail to validate closed state in set ...)
zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.
zstd-jni versions before 1.5.7-14 fail to validate closed state in set ...
zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.
Уязвимость функций setDict(), setLongMax() и setLevel() библиотеки сжатия данных zstd-jni, позволяющая нарушителю вызвать отказ в обслуживании
EPSS
7.7 High
CVSS3