Impact
The vulnerability resides in the constructor of the ZstdDictDecompress class in the zstd‑jni library. Offset and length arguments are not validated against the bounds of the supplied dictionary byte array, allowing an attacker to supply values that cause the Java Virtual Machine to read memory past the array’s end. The result is a JVM termination, which manifests as a denial‑of‑service condition. Because the out‑of‑bounds read does not leak data, there is no direct confidentiality or integrity impact, and code execution is not granted by the flaw itself.
Affected Systems
The zstd‑jni Java library, released by the luben community, is affected for versions 1.2.0 through 1.5.7‑13 inclusive. Any application that creates a Zstd decoder is vulnerable. An updated release, 1.5.7‑14 or later, adds the missing bounds check and mitigates the problem.
Risk and Exploitability
The CVSS score of 8.8 signals high severity. The EPSS score is < 1%, indicating a very low but nonzero likelihood of exploitation. The flaw is not listed in the CISA KEV catalog. Exploitability requires the ability to influence the offset and length values supplied to the constructor, which typically means the attacker has control over the data passed to the decompression routine. Successful exploitation will likely crash the Java process, potentially interrupting services, but it does not directly lead to data exfiltration or remote code execution.
OpenCVE Enrichment