yawkat LZ4 Java 为 Java 提供了 LZ4 压缩功能。在版本 1.11.4 之前,net.jpountz.lz4.LZ4FrameInputStream 类的 readHeader() 方法在读取最大块大小的帧头时,会分配两个新的 4 MiB 块缓冲区。默认启用的“连接帧”(concatenated-frame)模式允许攻击者构造包含大量极小空帧的数据流,从而每读取约 11 字节的输入数据即可触发约 8 MiB 的内存分配。由于该流在解压过程中不产生任何解压输出,但会持续消耗 CPU 和垃圾回收时
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106451 | 7.3 HIGH | yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable t |
| CVE-2026-106452 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the s |
| CVE-2026-106453 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte |
| CVE-2026-106449 | 3.7 LOW | yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty b |
No comments yet