Intel

AIKIDO-2026-569174

zstd-jni is vulnerable to Use-After-Free

Use-After-FreeCVE-2026-90852 Published 2 days ago

73

High Risk

This Affects:

JAVAzstd-jni
1.4.4-2 - 1.5.7-13
Fixed in 1.5.7-14
Are you affected? Scan for Free

TL;DR

ZstdCompressCtx.loadDict takes the dictionary lock, stores the native dictionary pointer, and releases the lock before later compression calls. Closing the dictionary frees that native object while the context still uses the pointer, so the next compress call uses freed memory and can crash the JVM. The fix keeps the dictionary lock until the context is closed.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your code closes a dictionary after ZstdCompressCtx.loadDict.

Background info

zstd-jni is vulnerable to Use-After-Free in versions 1.4.4-2 - 1.5.7-13.

How to fix this

Upgrade the com.github.luben:zstd-jni library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform