Описание
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.
A flaw was found in zstd-jni. This vulnerability, an out-of-bounds read, occurs in the ZstdDictDecompress constructor due to insufficient validation of offset and length arguments against dictionary array bounds. A remote attacker could exploit this by providing specially crafted input, leading to memory being read beyond its allocated buffer. This could result in the termination of the Java Virtual Machine (JVM), causing a denial of service.
Отчет
Red Hat has determined that affected versions of zstd-jni are vulnerable to an out-of-bounds read in the ZstdDictDecompress constructor. An attacker who can cause an application to supply invalid dictionary offset or length values may terminate the Java Virtual Machine, resulting in denial of service. Red Hat is tracking fixes for affected products.
Меры по смягчению последствий
Until a fixed update is available, applications should validate that dictionary offset and length values are non-negative and that the requested range does not exceed the dictionary array. Apply product updates containing zstd-jni 1.5.7-14 or a Red Hat backport of the fix when available.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Exploit Intelligence | exploit-intelligence/agent-client-rhel9 | Affected | ||
| OpenShift Developer Tools and Services | jenkins-2-plugins | Affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel8 | Affected | ||
| OpenShift Developer Tools and Services | ocp-tools-4/jenkins-rhel9 | Affected | ||
| Red Hat AMQ Clients | zstd-jni | Affected | ||
| Red Hat build of Apache Camel 4 for Quarkus 3 | zstd-jni | Affected | ||
| Red Hat build of Apache Camel for Spring Boot 4 | zstd-jni | Affected | ||
| Red Hat build of Apicurio Registry 3 | zstd-jni | Affected | ||
| Red Hat build of Debezium 3 | zstd-jni | Affected | ||
| Red Hat build of Quarkus | zstd-jni | Affected |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
EPSS
8.2 High
CVSS3
Связанные уязвимости
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read ...
zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.
EPSS
8.2 High
CVSS3