Impact
snappy-java versions up to 1.1.10.8 contain a buffer overflow in the typed Snappy.uncompress*Array methods. The methods allocate output arrays by dividing the reported uncompressed length by the element size, yet they pass the full uncompressed length to the native decompression routine. An attacker can craft compressed input that contains a length value misaligned with the element size, causing the native code to write past the array boundaries. This heap corruption can lead to arbitrary code execution if the application processes attacker‑controlled compressed data. The vulnerability is specifically within the native code invoked by Java, so the impact manifests as a failure of memory safety within a Java process that can be leveraged to execute code. The nature of the flaw is a classic buffer overflow (CWE-787) caused by improper bounds checking between Java and native layers, coupled with memory reuse and alignment issues (CWE-131) arising from dividing uncompressed length by element size while passing the undivided length to native code.
Affected Systems
The vulnerability affects the snappy-java library released by xerial. All releases up through 1.1.10.8 are affected; no other vendors or products are listed.
Risk and Exploitability
The CVSS score of 6.9 indicates a Medium severity vulnerability. The EPSS score is below 1 %, suggesting a low probability that exploit code will be seen in the wild. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an application to invoke the vulnerable native uncompress*Array methods with attacker‑controlled compressed input. If the application runs with sufficient privileges, a successful exploitation could give an attacker arbitrary code execution on the host. The description does not mention network reachability, so the most likely attack vector is an application that accepts externally supplied compressed data, such as a remote service or file upload endpoint.
OpenCVE Enrichment