Intel

AIKIDO-2026-989226

zstd-jni is vulnerable to Out-of-bounds Read

Out-of-bounds ReadCVE-2026-87824 Published 2 days ago

75

High Risk

This Affects:

JAVAzstd-jni
1.3.3-1 - 1.5.7-13
Fixed in 1.5.7-14
Are you affected? Scan for Free

TL;DR

Zstd.trainFromBufferDirect checks the dictionary buffer capacity but not the samples buffer. Each entry in sampleSizes is copied into the native trainer, so a sum larger than samples.capacity() makes the trainer read past the buffer and crash the JVM. The fix rejects a negative sample size and a total that exceeds the samples buffer.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range and your code calls Zstd.trainFromBufferDirect.

Background info

zstd-jni is vulnerable to Out-of-bounds Read in versions 1.3.3-1 - 1.5.7-13.

How to fix this

Upgrade the com.github.luben:zstd-jni library to the patch version.

Are You Affected?

Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.

Free. No credit card required.

Aikido Platform