SB20260930113 - Multiple vulnerabilities in lz4-java



SB20260930113 - Multiple vulnerabilities in lz4-java

Published: September 30, 2026

Security Bulletin ID SB20260930113
CSH Severity
Medium
Patch available
YES
Number of vulnerabilities 3
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

Medium 33% Low 67%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 3 vulnerabilities.


1) Time-of-check Time-of-use (TOCTOU) Race Condition (CVE-ID: N/A)

CWE-ID: CWE-367 - Time-of-check Time-of-use (TOCTOU) Race Condition

CVSSv4: 7.3 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a local user to execute arbitrary code as the victim process.

The vulnerability exists due to a time-of-check time-of-use race condition in net.jpountz.util.Native.load() when extracting the bundled native library to java.io.tmpdir. A local user can create and replace the predictable native library file before it is loaded to execute arbitrary code as the victim process.

Exploitation requires a shared writable temporary directory, host settings that permit file replacement, and winning a race.


2) Uncontrolled Recursion (CVE-ID: N/A)

CWE-ID: CWE-674 - Uncontrolled Recursion

CVSSv4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to uncontrolled recursion in net.jpountz.lz4.LZ4BlockInputStream.refill() when processing consecutive empty blocks in LZ4Block streams with stopOnEmptyBlock set to false. A remote attacker can supply a stream containing a long run of empty blocks to cause a denial of service.

The default stopOnEmptyBlock=true configuration is not affected.


3) Allocation of Resources Without Limits or Throttling (CVE-ID: N/A)

CWE-ID: CWE-770 - Allocation of Resources Without Limits or Throttling

CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to allocation of resources without limits or throttling in LZ4FrameInputStream.readHeader() when processing concatenated LZ4 frames. A remote attacker can send many minimal empty LZ4 frames to cause a denial of service.

Single-frame mode is not affected.


Remediation

Install update from vendor's website.