Описание
zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes.
A flaw was found in zstd-jni. This out-of-bounds read vulnerability in the Zstd.getFrameContentSize function occurs because it fails to validate negative srcPosition arguments. A remote attacker can supply negative offset values, bypassing bounds checks and accessing the native frame-header parser. This can lead to out-of-bounds memory reads, resulting in information disclosure or a Java Virtual Machine (JVM) crash.
Отчет
Red Hat is aware of an out-of-bounds read in zstd-jni when a negative source position is supplied to Zstd.getFrameContentSize. This may disclose native memory or cause a JVM crash. Affected Red Hat products are tracked for updates containing zstd-jni 1.5.7-14 or later.
Меры по смягчению последствий
Update to a product release containing zstd-jni 1.5.7-14 or later. Until updated, validate source positions and reject negative offsets before calling Zstd.getFrameContentSize. Do not pass attacker-controlled offsets to this method without validation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence/agent-client-rhel9 | Affected | ||
| OpenShift Developer Tools and Services | jenkins-2-plugins | Affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | zstd-jni | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | zstd-jni | Affected | ||
| Red Hat build of Apicurio Registry 3 | zstd-jni | Affected | ||
| Red Hat build of Debezium 3 | zstd-jni | Affected | ||
| Red Hat build of Quarkus | zstd-jni | Affected | ||
| Red Hat Ceph Storage 9 | libarrow | Fix deferred |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
8.2 High
CVSS3
Связанные уязвимости
(zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds re ...)
zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes.
zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds re ...
zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds read vulnerability in Zstd.getFrameContentSize that fails to validate negative srcPosition arguments. Attackers can supply negative offset values that bypass bounds checks and reach the native frame-header parser, causing out-of-bounds memory reads that lead to information disclosure or JVM crashes.
8.2 High
CVSS3