Description
A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after free. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.7-14 is able to resolve this issue. The name of the patch is a560131d7834598afd9cea6b7c107bc88e915936. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Published: 2026-09-15
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Remote Exploitation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability is a use‑after‑free in the ZstdCompressCtx.loadDict function. By manipulating dictionary sharing, an attacker can cause the library to reference freed memory during compression. Based on the description, it is inferred that accessing freed memory could lead to memory corruption, loss of confidentiality or integrity, or an application crash. The flaw is classified as CWE‑119, CWE‑416, and CWE‑825.

Affected Systems

All releases of the luben zstd‑jni library up to and including version 1.5.7‑13 are affected. Any system that loads the vulnerable library from a remote or untrusted source could be impacted. Installing version 1.5.7‑14, which incorporates the patch identified by commit a560131d7834598afd9cea6b7c107bc88e915936, eliminates the flaw.

Risk and Exploitability

The CVSS score of 6.9 signals moderate severity. The EPSS score is below 1 %, indicating a low probability of widespread exploitation, and the vulnerability has not been listed in CISA’s KEV catalog. The flaw can be exploited remotely by supplying crafted input that triggers the dictionary sharing path. Based on the description, it is inferred that attackers who can influence data passed to the library may trigger memory corruption; thus the risk is moderate but significant for exposed applications.

Generated by OpenCVE AI on September 17, 2026 at 18:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to version 1.5.7‑14 or later, which contains the official fix.
  • If an immediate upgrade is not possible, apply the upstream patch corresponding to commit a560131d7834598afd9cea6b7c107bc88e915936 to the source and rebuild the library.
  • Add defensive checks in your application code to ensure that dictionary references are not used after they have been released, and review any custom dictionary handling logic for proper memory management.

Generated by OpenCVE AI on September 17, 2026 at 18:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 15 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-825
References
Metrics threat_severity

None

threat_severity

Important


Tue, 15 Sep 2026 02:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after free. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.7-14 is able to resolve this issue. The name of the patch is a560131d7834598afd9cea6b7c107bc88e915936. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Title luben zstd-jni Dictionary Sharing ZstdCompressCtx.java ZstdCompressCtx.loadDict use after free
First Time appeared Luben
Luben zstd-jni
Weaknesses CWE-119
CWE-416
CPEs cpe:2.3:a:luben:zstd-jni:*:*:*:*:*:*:*:*
Vendors & Products Luben
Luben zstd-jni
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T18:19:04.282Z

Reserved: 2026-09-14T05:37:05.957Z

Link: CVE-2026-90852

cve-icon Vulnrichment

Updated: 2026-09-15T18:18:55.544Z

cve-icon NVD

Status : Deferred

Published: 2026-09-15T03:17:06.377

Modified: 2026-09-15T19:17:46.910

Link: CVE-2026-90852

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-15T02:15:10Z

Links: CVE-2026-90852 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-09-17T21:00:17Z

Weaknesses
  • CWE-119

    Improper Restriction of Operations within the Bounds of a Memory Buffer

  • CWE-416

    Use After Free

  • CWE-825

    Expired Pointer Dereference