Junglewise Threat Intelligence

CVE-2026-32829: PSeitz lz4_flex information disclosure in block decompression APIs

CVE-2026-32829 · Severity: high · CVSS 7.5 · Published 2026-03-20

Vendors: crates.io.

Executive brief

lz4_flex is a software library used to compress and decompress data efficiently. A security flaw in certain versions allows a malicious actor to provide specially crafted data that, when decompressed, reveals sensitive information from the computer's memory or from previous operations. This could lead to the exposure of private data or secrets handled by the application using this library.

Technical details

An information disclosure vulnerability exists in lz4_flex due to improper validation of offset values during LZ4 'match copy operations.' When decompressing malformed LZ4 data, the library may perform an out-of-bounds read from the output buffer, copying uninitialized memory or data from previous decompression cycles into the result. The issue specifically affects block-based API functions such as `decompress_into` and `decompress_into_with_dict`. If the `safe-decode` feature is disabled, additional functions like `decompress` and `decompress_size_prepended` are also vulnerable. The vulnerability is fixed in versions 0.11.6 and 0.12.1.

Affected products

  • PSeitz lz4_flex <= 0.11.5, 0.12.0

Timeline

  • 2026-03-14: patched: Fix committed and advisory published by maintainer
  • 2026-03-20: disclosed: NVD publication date

References