Impact
The vulnerability is a use‑after‑free in the ZstdCompressCtx.loadDict function. By manipulating dictionary sharing, an attacker can cause the library to reference freed memory during compression. Based on the description, it is inferred that accessing freed memory could lead to memory corruption, loss of confidentiality or integrity, or an application crash. The flaw is classified as CWE‑119, CWE‑416, and CWE‑825.
Affected Systems
All releases of the luben zstd‑jni library up to and including version 1.5.7‑13 are affected. Any system that loads the vulnerable library from a remote or untrusted source could be impacted. Installing version 1.5.7‑14, which incorporates the patch identified by commit a560131d7834598afd9cea6b7c107bc88e915936, eliminates the flaw.
Risk and Exploitability
The CVSS score of 6.9 signals moderate severity. The EPSS score is below 1 %, indicating a low probability of widespread exploitation, and the vulnerability has not been listed in CISA’s KEV catalog. The flaw can be exploited remotely by supplying crafted input that triggers the dictionary sharing path. Based on the description, it is inferred that attackers who can influence data passed to the library may trigger memory corruption; thus the risk is moderate but significant for exposed applications.
OpenCVE Enrichment