zstd-jni is vulnerable to Out-of-bounds Read
75
High Risk
Zstd.trainFromBufferDirect checks the dictionary buffer capacity but not the samples buffer. Each entry in sampleSizes is copied into the native trainer, so a sum larger than samples.capacity() makes the trainer read past the buffer and crash the JVM. The fix rejects a negative sample size and a total that exceeds the samples buffer.
You are affected if you are using a version that falls within the vulnerable range and your code calls Zstd.trainFromBufferDirect.
zstd-jni is vulnerable to Out-of-bounds Read in versions 1.3.3-1 - 1.5.7-13.
Upgrade the com.github.luben:zstd-jni library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.