yawkat LZ4 Java 为 Java 提供了 LZ4 压缩支持。在版本 1.11.4 之前,当 被配置为将 设置为 时,会对每个格式正确的空 LZ4Block 递归调用 方法进行处理。攻击者通过在可控的压缩数据流中插入大量空块,可耗尽解码线程的栈空间,从而引发 (栈溢出错误)。 默认情况下, 的配置值为 ,因此不受此漏洞影响。此外,该问题不会导致内存损坏。此问题已在版本 1.11.4 中得到修复。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106451 | 7.3 HIGH | yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable t |
| CVE-2026-106452 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the s |
| CVE-2026-106450 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing C |
| CVE-2026-106453 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte |
No comments yet