Executive brief
zstd-jni is a Java library that provides compression/decompression functionality using the Zstandard algorithm. A flaw in the ZstdInputStreamNoFinalizer.read() method fails to validate negative length parameters, allowing an attacker to trigger infinite loops that freeze the stream and block all other threads from using it, causing a denial of service.
Technical details
The vulnerability is an input validation flaw in the ZstdInputStreamNoFinalizer.read() method, which does not properly check for negative length parameters. When a negative length value is passed to the read() method, it enters an infinite loop while holding the stream's monitor lock, preventing other threads from accessing the stream. The affected versions are 1.4.8-4 through 1.5.7-13. This is a local or adjacent network attack that requires the attacker to be able to invoke the vulnerable method with a malicious parameter; no authentication bypass or remote exploitation is involved. A patch is available in version 1.5.7-14 and later.
Affected products
- Luben zstd-jni 1.4.8-4 through 1.5.7-13
Timeline
- 2026-09-10: disclosed
- 2026-08-16: other: Version 1.5.7-14 released with fix (prior to disclosure)