Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2026-87795

Опубликовано: 10 сент. 2026
Источник: ubuntu
Приоритет: medium
EPSS Низкий
CVSS3: 8.2

Описание

(zstd-jni versions before 1.5.7-14 fail to validate offset and length p ...)

РелизСтатусПримечание
devel

needs-triage

esm-apps/noble

needs-triage

esm-apps/resolute

needs-triage

jammy

DNE

noble

needs-triage

resolute

needs-triage

upstream

needs-triage

Показывать по

EPSS

Процентиль: 28%
0.00344
Низкий

8.2 High

CVSS3

Связанные уязвимости

CVSS3: 8.2
redhat
7 дней назад

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

CVSS3: 8.2
nvd
7 дней назад

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

CVSS3: 8.2
debian
7 дней назад

zstd-jni versions before 1.5.7-14 fail to validate offset and length p ...

CVSS3: 8.2
github
7 дней назад

zstd-jni versions before 1.5.7-14 fail to validate offset and length parameters in the ZstdDictCompress constructor, allowing out-of-bounds memory reads. Attackers can supply untrusted offset or length values to read native heap memory into the compression dictionary, typically causing JVM crashes.

CVSS3: 8.2
fstec
около 1 месяца назад

Уязвимость компонента ZstdDictCompress библиотеки сжатия данных zstd-jni, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 28%
0.00344
Низкий

8.2 High

CVSS3