Out-of-bounds read in lz4-java - CVE-2025-12183

 

Out-of-bounds read in lz4-java - CVE-2025-12183

Published: January 7, 2026


Vulnerability identifier: #VU121006
CSH Severity: Medium
CVSS v4: 8.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-12183
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to potentially sensitive information or perform a denial of service attack.

The vulnerability exists due to a boundary condition. A remote attacker can pass specially crafted compressed input to the application, trigger an out-of-bounds read error and read contents of memory on the system or perform a denial of service attack.


Affected software

lz4-java
Log Analysis
IBM Watson Discovery for IBM Cloud Pak for Data
IBM Cloud Application Performance Management (APM)
Oracle JDK Mission Control
Red Hat build of Quarkus
IBM Maximo Application Suite - Manage Component
App Connect Enterprise Certified Container
Enterprise Build of Quarkus
IBM Business Automation Manager Open Editions
webMethods BPM
IBM Qradar SIEM
IBM InfoSphere Information Server
Oracle Banking Liquidity Management
IBM Disconnected Log Collector

How to mitigate CVE-2025-12183

Install updates from vendor's website.

lz4-java - update to 1.8.1
Log Analysis - update to 1.3.8.3 IF001
Enterprise Build of Quarkus - update to 3.27.1.SP1
IBM Watson Discovery for IBM Cloud Pak for Data - update to 5.3.1
IBM Qradar SIEM - update to 7.5.0 Update Pack 15 IF05
IBM Cloud Application Performance Management (APM) - update to 8.1.4.0.19
IBM Business Automation Manager Open Editions - update to 9.3.1
IBM InfoSphere Information Server - update to 11.7.1.6 Service pack 1
IBM Disconnected Log Collector - update to 2.0.1
Red Hat build of Quarkus - addressed in versions 3.20.4.SP1, 3.27.1.SP1
IBM Maximo Application Suite - Manage Component - addressed in versions 8.6.34, 8.7.28, 9.0.21, 9.1.8
webMethods BPM - update to 11.1 Fix 9
App Connect Enterprise Certified Container - addressed in versions 12.0.23, 13.1.0

External References

Related Security Bulletins