Description
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2.
Published: 2026-10-06
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Heap exhaustion resulting in denial of service
Action: Apply update
AI Analysis

Impact

A crafted LZ4 block stream can cause the LZ4BlockInputStream to allocate a buffer whose size is taken directly from an unvalidated field in the stream header. The likely attack vector is through a malicious LZ4 stream supplied to the library; this is inferred because the vulnerability requires the library to read a header from external data. The attacker can request a size close to 2 GiB, resulting in an out‑of‑memory condition that crashes the Java process or causes it to become unresponsive. The vulnerability demonstrates a classic out‑of‑bounds allocation flaw, providing an attacker with the ability to exhaust the JVM heap and disrupt application availability. The weakness is classified as CWE‑789.

Affected Systems

The yawkat LZ4 Java library, in all versions prior to 1.11.2, is affected. Users of the net.jpountz.lz4.LZ4BlockInputStream class that process externally supplied LZ4 data must ensure they are using 1.11.2 or newer.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate impact. Because the exploit relies on supplying an engineered compressed block, the attack is likely limited to scenarios where the library processes untrusted data. The likely attack vector is when the library receives an untrusted LZ4 stream; this is inferred because the vulnerability requires processing of a crafted header, which typically originates from external payload. EPSS is not available, so the probability of exploitation cannot be quantified; the vulnerability is not listed in CISA KEV, suggesting no known exploit in the wild. Nonetheless, due to the potential for heap exhaustion and the moderate severity, the risk is non‑negligible for services that accept large or untrusted LZ4 payloads.

Generated by OpenCVE AI on October 7, 2026 at 01:13 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade yawkat lz4-java to version 1.11.2 or later to eliminate the unchecked buffer allocation.
  • If upgrading is not immediately possible, add a pre‑check to reject compressed block headers that specify a compressed length beyond a safe threshold before allocating memory, effectively preventing the problematic allocation.
  • Ensure that any untrusted LZ4 data is processed in a sandboxed or secured environment with memory limits, and monitor JVM memory usage for anomalous spikes during decoding operations.

Generated by OpenCVE AI on October 7, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 00:30:00 +0000

Type Values Removed Values Added
First Time appeared Yawkat
Yawkat lz4-java
Vendors & Products Yawkat
Yawkat lz4-java

Tue, 06 Oct 2026 20:00:00 +0000

Type Values Removed Values Added
Description yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2.
Title yawkat LZ4 Java: LZ4BlockInputStream allocates an unvalidated compressed length from the stream header
Weaknesses CWE-789
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-10-06T19:52:37.818Z

Reserved: 2026-10-06T16:49:40.591Z

Link: CVE-2026-106452

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-06T20:17:27.317

Modified: 2026-10-06T20:17:27.317

Link: CVE-2026-106452

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T01:15:09Z

Weaknesses
  • CWE-789

    Memory Allocation with Excessive Size Value