zstd-jni 1.5.7-14 之前的版本未能对 stream 类的 、 、 和 方法进行关闭状态校验。攻击者可以在已关闭的流上调用这些方法,从而通过已释放的原生指针进行写入,导致无关对象损坏或导致 JVM 崩溃。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-87795 | 8.2 HIGH | zstd-jni 1.2.0 through 1.5.7-13 Out-of-Bounds Read via ZstdDictCompress |
| CVE-2026-87823 | 8.2 HIGH | zstd-jni 1.1.1 through 1.5.7-13 Out-of-Bounds Read via Direct ByteBuffer Frame-Size Method |
| CVE-2026-87825 | 7.7 HIGH | zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free of Compression and Decompression Dictiona |
| CVE-2026-87824 | 7.5 HIGH | zstd-jni 1.3.3-1 through 1.5.7-13 Out-of-Bounds Read via Zstd.trainFromBufferDirect |
No comments yet