Impact
A crafted LZ4 block stream can cause the LZ4BlockInputStream to allocate a buffer whose size is taken directly from an unvalidated field in the stream header. The likely attack vector is through a malicious LZ4 stream supplied to the library; this is inferred because the vulnerability requires the library to read a header from external data. The attacker can request a size close to 2 GiB, resulting in an out‑of‑memory condition that crashes the Java process or causes it to become unresponsive. The vulnerability demonstrates a classic out‑of‑bounds allocation flaw, providing an attacker with the ability to exhaust the JVM heap and disrupt application availability. The weakness is classified as CWE‑789.
Affected Systems
The yawkat LZ4 Java library, in all versions prior to 1.11.2, is affected. Users of the net.jpountz.lz4.LZ4BlockInputStream class that process externally supplied LZ4 data must ensure they are using 1.11.2 or newer.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate impact. Because the exploit relies on supplying an engineered compressed block, the attack is likely limited to scenarios where the library processes untrusted data. The likely attack vector is when the library receives an untrusted LZ4 stream; this is inferred because the vulnerability requires processing of a crafted header, which typically originates from external payload. EPSS is not available, so the probability of exploitation cannot be quantified; the vulnerability is not listed in CISA KEV, suggesting no known exploit in the wild. Nonetheless, due to the potential for heap exhaustion and the moderate severity, the risk is non‑negligible for services that accept large or untrusted LZ4 payloads.
OpenCVE Enrichment