Junglewise Threat Intelligence

CVE-2026-87825: zstd-jni use-after-free in dictionary reference handling

CVE-2026-87825 · Severity: high · CVSS 7.7 · Published 2026-09-09

Technologies: Luben Zstd-Jni. Vendors: Luben.

Executive brief

zstd-jni is a Java library that provides compression functionality through native bindings to the Zstandard compression algorithm. A use-after-free vulnerability allows attackers to close a dictionary after it has been associated with a compression or decompression stream, causing the library to access freed memory. This can result in silent data corruption (compressed data becoming invalid or decompressed data becoming corrupted) or crash the Java Virtual Machine, disrupting any application relying on this compression library.

Technical details

The vulnerability is a use-after-free flaw in zstd-jni's dictionary lifecycle management. Streams and contexts hold only a shared lock on a dictionary during the initial load call, but release the lock immediately afterward. An attacker can explicitly close the dictionary object while it remains referenced by an active stream or context, causing subsequent read or write operations to dereference freed native memory. The vulnerability is triggered through normal API usage without requiring special privileges or network access, though the attacker must have the ability to control when the dictionary is closed. Patch is available in version 1.5.7-14 and later.

Affected products

  • Luben zstd-jni before 1.5.7-14

Timeline

  • 2026-09-09: disclosed
  • 2026-08-16: patched: Fix available in version 1.5.7-14 released 2026-08-16

References

Related threats