yawkat 公司的 LZ4 Java 库为 Java 应用程序提供 LZ4 压缩功能。在版本 1.11.2 之前, 类中的 方法会验证传统 LZ4Block 头部中 字段为非负数,但在读取有效载荷数据之前,该方法会根据攻击者可控制的该值分配一个压缩输入缓冲区。这使得仅包含头部的流可以请求接近 2 GiB 的内存分配,从而导致 JVM 堆内存耗尽。 尽管标准(规范)LZ4 写入器在压缩后的数据不比原始块更小时会直接输出原始块,但存在漏洞的读取器却接受非规范(非标准)的 oversized( oversized 指超
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106451 | 7.3 HIGH | yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable t |
| CVE-2026-106450 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing C |
| CVE-2026-106453 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte |
| CVE-2026-106449 | 3.7 LOW | yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty b |
No comments yet