Количество 6
Количество 6
CVE-2026-87825
(zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where ...)
CVE-2026-87825
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes.
CVE-2026-87825
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes.
CVE-2026-87825
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where ...
GHSA-9p7w-x2w6-p34j
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes.
BDU:2026-14469
Уязвимость компонентов ZstdCompressCtx и ZstdDecompressCtx библиотеки сжатия данных zstd-jni, позволяющая нарушителю вызвать отказ в обслуживании
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-87825 (zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where ...) | CVSS3: 7.7 | 0% Низкий | 6 дней назад | |
CVE-2026-87825 zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes. | CVSS3: 7.7 | 0% Низкий | 7 дней назад | |
CVE-2026-87825 zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes. | CVSS3: 7.7 | 0% Низкий | 7 дней назад | |
CVE-2026-87825 zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where ... | CVSS3: 7.7 | 0% Низкий | 7 дней назад | |
GHSA-9p7w-x2w6-p34j zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes. | CVSS3: 7.7 | 0% Низкий | 7 дней назад | |
BDU:2026-14469 Уязвимость компонентов ZstdCompressCtx и ZstdDecompressCtx библиотеки сжатия данных zstd-jni, позволяющая нарушителю вызвать отказ в обслуживании | CVSS3: 7.7 | 0% Низкий | около 1 месяца назад |
Уязвимостей на страницу