zstd-jni is vulnerable to Integer Overflow
57
Medium Risk
decompressedDirectByteBufferSize, getDirectByteBufferFrameContentSize, and findDirectByteBufferFrameCompressedSize add src_offset and src_size as signed 32-bit integers. A negative value or a sum that wraps makes the bounds check succeed, and the native code then reads outside the direct buffer and can crash the JVM. The fix rejects negative values and checks that the offset is not past the remaining buffer.
You are affected if you are using a version that falls within the vulnerable range and your code calls the direct ByteBuffer frame size methods.
zstd-jni is vulnerable to Integer Overflow in versions 1.1.1 - 1.5.7-13.
Upgrade the com.github.luben:zstd-jni library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.