yawkat LZ4 Java 为 Java 提供了 LZ4 压缩支持。从版本 1.7.0 到 1.11.4, 方法使用 创建一个独占的临时 文件,但在推导本地库路径时,它仅通过移除后缀来获取路径,随后使用 以非独占方式打开该可预测的路径。这允许同一共享临时目录中的其他本地用户在 加载库之前创建或替换该库文件,从而构成竞争条件漏洞。成功利用此漏洞依赖于共享目录的权限设置、主机系统的安全防护措施以及是否能在竞争中胜出。利用成功后,攻击者可以以受害者身份执行原生代码;而在加固后的系统中,可能导致库加载失败,进而回退到纯
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106452 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the s |
| CVE-2026-106450 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing C |
| CVE-2026-106453 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte |
| CVE-2026-106449 | 3.7 LOW | yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty b |
No comments yet