zstd-jni 1.4.8-4 through 1.5.7-13 Denial of Service via Negative Length
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.1epss 0.1%
exploitation probability
0.1%top 97% of all CVEs
observed exploitation
nono source reports it
zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative length parameters in ZstdInputStreamNoFinalizer.read(), allowing attackers to trigger infinite loops. Attackers can pass negative length values to cause the read method to spin indefinitely while holding the stream monitor, blocking all other threads from accessing the stream.
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Affected products
luben · zstd-jniReferences
https://github.com/luben/zstd-jnihttps://github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/ZstdInputStreamNoFinalizer.java#L133https://github.com/luben/zstd-jni/commit/dd08685ef913a32e76fb27f43470035c06758646https://github.com/luben/zstd-jni/releases/tag/v1.5.7-14https://github.com/luben/zstd-jni/security/advisories/GHSA-9jx2-gfp9-phfmhttps://www.vulncheck.com/advisories/zstd-jni-1.4.8-4-through-1.5.7-13-denial-of-service-via-negative-length