Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-90560

Опубликовано: 12 сент. 2026
Источник: redhat
CVSS3: 8.2
EPSS Низкий

Описание

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.

A flaw was found in zstd-jni. This vulnerability, an out-of-bounds read, occurs in the ZstdDictDecompress constructor due to insufficient validation of offset and length arguments against dictionary array bounds. A remote attacker could exploit this by providing specially crafted input, leading to memory being read beyond its allocated buffer. This could result in the termination of the Java Virtual Machine (JVM), causing a denial of service.

Отчет

Red Hat has determined that affected versions of zstd-jni are vulnerable to an out-of-bounds read in the ZstdDictDecompress constructor. An attacker who can cause an application to supply invalid dictionary offset or length values may terminate the Java Virtual Machine, resulting in denial of service. Red Hat is tracking fixes for affected products.

Меры по смягчению последствий

Until a fixed update is available, applications should validate that dictionary offset and length values are non-negative and that the requested range does not exceed the dictionary array. Apply product updates containing zstd-jni 1.5.7-14 or a Red Hat backport of the fix when available.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Exploit Intelligenceexploit-intelligence/agent-client-rhel9Affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsAffected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel8Affected
OpenShift Developer Tools and Servicesocp-tools-4/jenkins-rhel9Affected
Red Hat AMQ Clientszstd-jniAffected
Red Hat build of Apache Camel 4 for Quarkus 3zstd-jniAffected
Red Hat build of Apache Camel for Spring Boot 4zstd-jniAffected
Red Hat build of Apicurio Registry 3zstd-jniAffected
Red Hat build of Debezium 3zstd-jniAffected
Red Hat build of Quarkuszstd-jniAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2532604com.github.luben/zstd-jni: zstd-jni: Denial of Service via out-of-bounds read in ZstdDictDecompress

EPSS

Процентиль: 27%
0.00336
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
ubuntu
5 дней назад

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.

CVSS3: 8.2
nvd
5 дней назад

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.

CVSS3: 8.2
debian
5 дней назад

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read ...

CVSS3: 8.2
github
5 дней назад

zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.

EPSS

Процентиль: 27%
0.00336
Низкий

8.2 High

CVSS3