SB20260930113 - Multiple vulnerabilities in lz4-java
Published: September 30, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 3 vulnerabilities.
1) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: N/A)
CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition
CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a local user to execute arbitrary code as the victim process.
The vulnerability exists due to a time-of-check time-of-use race condition in net.jpountz.util.Native.load() when extracting the bundled native library to java.io.tmpdir. A local user can create and replace the predictable native library file before it is loaded to execute arbitrary code as the victim process.
Exploitation requires a shared writable temporary directory, host settings that permit file replacement, and winning a race.
2) Uncontrolled Recursion (CVE-ID: N/A)
CWE-ID: CWE-674 - Uncontrolled Recursion
CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to uncontrolled recursion in net.jpountz.lz4.LZ4BlockInputStream.refill() when processing consecutive empty blocks in LZ4Block streams with stopOnEmptyBlock set to false. A remote attacker can supply a stream containing a long run of empty blocks to cause a denial of service.
The default stopOnEmptyBlock=true configuration is not affected.
3) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)
CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to allocation of resources without limits or throttling in LZ4FrameInputStream.readHeader() when processing concatenated LZ4 frames. A remote attacker can send many minimal empty LZ4 frames to cause a denial of service.
Single-frame mode is not affected.
Remediation
Install update from vendor's website.