Impact
snappy-java versions up to 1.1.10.8 contain an out‑of‑bounds write vulnerability in the uncompress(ByteBuffer, ByteBuffer) method because the destination buffer’s capacity is never checked against the decompressed size. An attacker can supply a crafted compressed payload that expands beyond the buffer, causing data to be written past the end of the buffer. This memory corruption will result in a JVM crash and effectively deny service to the affected application. The weakness is a classic buffer overflow, classified under CWE-787.
Affected Systems
All releases of Xerial’s snappy-java library through 1.1.10.8 are vulnerable. Any software that incorporates this library—such as data processing frameworks, big‑data pipelines, or custom services—could be impacted if it ever processes untrusted compressed data.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity, while the EPSS score of < 1% suggests a very low yet non‑zero likelihood of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is via delivery of malicious compressed data to the uncompress method; this could be invoked either locally or remotely by any component that accepts externally sourced compressed streams. Based on the description it is inferred that an attacker can trigger the fault by supplying crafted data to the vulnerable method.
OpenCVE Enrichment