zstd-jni 在 1.5.7-14 版本之前,针对三个直接 ByteBuffer 帧大小原生方法执行 32 位有符号边界检查,允许通过负数或溢出的偏移量进行越界内存读取。攻击者可以提供接近 的负偏移值,从而读取未映射的内存,导致 JVM 终止或从非预期内存位置提取任意帧大小数据。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87795 | 8.2 HIGH | zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictCompress |
| CVE-2026-87877 | 7.7 HIGH | zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free via Setters Called After close() |
| CVE-2026-87825 | 7.7 HIGH | zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free of Compression and Decompression Dictiona |
| CVE-2026-87824 | 7.5 HIGH | zstd-jni 1.3.3-1 through 1.5.7-13 Out-of-Bounds Read via Zstd.trainFromBufferDirect |
No comments yet