HIGHMaven →
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
LZ4 Java: Native XXHash implementations can crash the JVM when passed invalid byte array ranges
Affected packages
- at.yawk.lz4:lz4-java— before 1.11.1
- org.lz4:lz4-java— all versions
Exploit signal
- Known exploited (CISA KEV)
- No
- EPSS score
- —
- EPSS percentile
- —
EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs.
Sources
- https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
- https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da
- https://github.com/yawkat/lz4-java
- https://github.com/yawkat/lz4-java/releases/tag/v1.11.1
Structured record: https://osv.dev/vulnerability/GHSA-xx22-p4ch-683r
Recommended response stack
Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.
Get incidents like this as alerts for your stack.
Join the beta