Executive brief
zstd-jni is a Java library that provides compression functionality via native bindings to the Zstandard algorithm. A flaw in the trainFromBufferDirect method fails to validate sample buffer sizes, allowing attackers to craft malicious input that reads beyond allocated memory boundaries. This can crash the Java Virtual Machine (JVM) and disrupt applications relying on this library for data compression tasks.
Technical details
The vulnerability is a classic out-of-bounds memory read flaw in the native implementation of Zstd.trainFromBufferDirect. The method accepts an array of per-sample lengths but fails to properly validate that these lengths do not cause buffer reads past the allocated sample buffer capacity. An attacker can supply crafted sample length values that cause the underlying native code to walk past buffer boundaries during the training operation. The attack is network-adjacent or local, depending on how the application exposes the trainFromBufferDirect API. Successful exploitation results in JVM termination. The fix is available in version 1.5.7-14 and later.
Affected products
- luben zstd-jni before 1.5.7-14
Timeline
- 2026-09-09: disclosed
- 2026-08-16: patched: Version 1.5.7-14 released