Impact
snappy-java versions up to 1.1.10.8 contain a buffer overflow in the Snappy.compress method. The vulnerability allows an attacker to write beyond the end of the destination ByteBuffer, corrupting off‑heap memory. This corruption can terminate the JVM.
Affected Systems
xerial's snappy-java library, versions up to 1.1.10.8, is affected by the buffer overflow. This includes any Java application that incorporates the vulnerable library and uses the Snappy.compress method on ByteBuffer inputs.
Risk and Exploitability
With a CVSS score of 8.7 the vulnerability is considered high severity, while an EPSS score of less than 1% indicates a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger the overflow by supplying incompressible data that exceeds the destination buffer's remaining capacity, a scenario that is inferred to occur when the application processes data that may be under the attacker's control.
OpenCVE Enrichment