Intel

AIKIDO-2026-954873

zstd-jni is vulnerable to Integer Overflow

Integer OverflowCVE-2026-87823 Published 2 days ago

57

Medium Risk

This Affects:

JAVAzstd-jni
1.1.1 - 1.5.7-13
Fixed in 1.5.7-14
Are you affected? Scan for Free

TL;DR

decompressedDirectByteBufferSize, getDirectByteBufferFrameContentSize, and findDirectByteBufferFrameCompressedSize add src_offset and src_size as signed 32-bit integers. A negative value or a sum that wraps makes the bounds check succeed, and the native code then reads outside the direct buffer and can crash the JVM. The fix rejects negative values and checks that the offset is not past the remaining buffer.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your code calls the direct ByteBuffer frame size methods.

Background info

zstd-jni is vulnerable to Integer Overflow in versions 1.1.1 - 1.5.7-13.

How to fix this

Upgrade the com.github.luben:zstd-jni library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform