Junglewise Threat Intelligence

CVE-2026-87824: zstd-jni out-of-bounds buffer read in trainFromBufferDirect

CVE-2026-87824 · Severity: high · CVSS 7.5 · Published 2026-09-09

Technologies: Luben Zstd-Jni. Vendors: Luben.

Executive brief

zstd-jni is a Java library that provides compression functionality via native bindings to the Zstandard algorithm. A flaw in the trainFromBufferDirect method fails to validate sample buffer sizes, allowing attackers to craft malicious input that reads beyond allocated memory boundaries. This can crash the Java Virtual Machine (JVM) and disrupt applications relying on this library for data compression tasks.

Technical details

The vulnerability is a classic out-of-bounds memory read flaw in the native implementation of Zstd.trainFromBufferDirect. The method accepts an array of per-sample lengths but fails to properly validate that these lengths do not cause buffer reads past the allocated sample buffer capacity. An attacker can supply crafted sample length values that cause the underlying native code to walk past buffer boundaries during the training operation. The attack is network-adjacent or local, depending on how the application exposes the trainFromBufferDirect API. Successful exploitation results in JVM termination. The fix is available in version 1.5.7-14 and later.

Affected products

  • luben zstd-jni before 1.5.7-14

Timeline

  • 2026-09-09: disclosed
  • 2026-08-16: patched: Version 1.5.7-14 released

References

Related threats