CVE-2026-106451: fallo de gravedad alta en yawkat lz4-java
yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user
Publicada el · Actualizada el
21Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 7.3epss 0.1%
probabilidad de explotación
0.1%top 100% de las CVE
explotación observada
noninguna fuente lo reporta
yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4.
CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Productos afectados
yawkat · lz4-javaCVEs relacionadas — yawkat lz4-java
En el mismo producto, de las más peligrosas a las menos.
CVE-2025-66566HIGHyawkat LZ4 Java has a possible information leak in Java safe decompressorEPSS 0.6%CVE-2026-59949MEDIUMyawkat LZ4 Java: JVM Crash via Null Byte Array in lz4-java Streaming XXHash JNI (StreamingXXHash32JNI / StreamingXXHash64JNI)EPSS 0.5%CVE-2026-106453MEDIUMyawkat LZ4 Java: LZ4DecompressorWithLength allocates the unvalidated size from the 4-byte length header, so a 5-byte input triggers a 1 GiB allocation and OutOfMemoryErrorEPSS 0.4%CVE-2026-106452MEDIUMyawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream headerEPSS 0.4%CVE-2026-106450MEDIUMyawkat LZ4 Java: LZ4FrameInputStream reallocates block buffers for every frame, allowing CPU and GC amplification from small inputsEPSS 0.4%CVE-2026-106449LOWyawkat LZ4 Java: LZ4BlockInputStream with stopOnEmptyBlock=false recurses once per empty block, causing StackOverflowErrorEPSS 0.3%