Executive brief
lz4_flex is a software library used to compress and decompress data efficiently. A security flaw in certain versions allows a malicious actor to provide specially crafted data that, when decompressed, reveals sensitive information from the computer's memory or from previous operations. This could lead to the exposure of private data or secrets handled by the application using this library.
Technical details
An information disclosure vulnerability exists in lz4_flex due to improper validation of offset values during LZ4 'match copy operations.' When decompressing malformed LZ4 data, the library may perform an out-of-bounds read from the output buffer, copying uninitialized memory or data from previous decompression cycles into the result. The issue specifically affects block-based API functions such as `decompress_into` and `decompress_into_with_dict`. If the `safe-decode` feature is disabled, additional functions like `decompress` and `decompress_size_prepended` are also vulnerable. The vulnerability is fixed in versions 0.11.6 and 0.12.1.
Affected products
- PSeitz lz4_flex <= 0.11.5, 0.12.0
Timeline
- 2026-03-14: patched: Fix committed and advisory published by maintainer
- 2026-03-20: disclosed: NVD publication date
References
- https://github.com/PSeitz/lz4_flex/commit/055502ee5d297ecd6bf448ac91c055c7f6df9b6d
- https://github.com/PSeitz/lz4_flex/security/advisories/GHSA-vvp9-7p8x-rfvv
- https://rustsec.org/advisories/RUSTSEC-2026-0041.html
- https://access.redhat.com/errata/RHSA-2026:11800
- https://access.redhat.com/errata/RHSA-2026:16354
- https://access.redhat.com/errata/RHSA-2026:19712
- https://access.redhat.com/errata/RHSA-2026:22862