yawkat LZ4 Java 为 Java 提供了 LZ4 压缩功能。在 1.11.2 版本之前,LZ4DecompressorWithLength 类在使用 getDecompressedLength 方法获取解压缩长度后,会无条件信任其读取的四个字节头中的“解压缩数据长度”字段,随后才对压缩输入数据进行验证。这使得攻击者只需提供长度为五个字节的恶意输入(其中四个字节头部声明一个极大的输出尺寸),即可要求分配高达约 2 GiB 的内存,从而耗尽 JVM 堆空间。 依赖于 LZ4FastDecompressor
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-106451 | 7.3 HIGH | yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable t |
| CVE-2026-106452 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the s |
| CVE-2026-106450 | 5.3 MEDIUM | yawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing C |
| CVE-2026-106449 | 3.7 LOW | yawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty b |
No comments yet