{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/zstd-jni--1.5.7-14/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:zstd-jni_project:zstd-jni:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-87824"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["zstd-jni (\u003c 1.5.7-14)","zstd-jni (1.5.5-6 to 1.5.7-13)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":[],"content_html":"\u003cp\u003eThe zstd-jni library, a Java wrapper for the Zstandard compression algorithm, contains a critical vulnerability in the Zstd.trainFromBufferDirect method. Versions prior to 1.5.7-14 fail to properly validate the capacity of the samples buffer when processing compression dictionary training data. By providing crafted per-sample length arrays, an attacker can force the native Zstandard implementation to access memory addresses beyond the allocated buffer boundaries. This out-of-bounds memory read causes a segmentation fault within the native library, which subsequently results in the abrupt termination of the Java Virtual Machine (JVM). This vulnerability poses a significant denial-of-service risk to any Java application that utilizes zstd-jni to process untrusted compression dictionary training data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability results in a high-severity denial-of-service condition due to the crash of the host JVM. Applications that accept user-provided training samples for Zstandard dictionary building are at risk of repeated service interruption or potential instability if the native memory corruption leads to unpredictable process states before the final crash occurs.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the zstd-jni dependency to version 1.5.7-14 or later to remediate CVE-2026-87824.\u003c/li\u003e\n\u003cli\u003eAudit all application entry points that pass user-supplied input to Zstd.trainFromBufferDirect to ensure that input length arrays are validated against expected bounds before processing.\u003c/li\u003e\n\u003cli\u003eMonitor application logs for sudden JVM process exits accompanied by native crash dumps (hs_err_pid files) that indicate errors within the libzstd-jni native library.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-10T19:08:07Z","date_published":"2026-09-09T16:58:46Z","id":"https://feed.craftedsignal.io/briefs/2026-09-zstd-jni-oob-read/","summary":"The zstd-jni library fails to validate sample buffer capacity in the Zstd.trainFromBufferDirect method, allowing attackers to trigger out-of-bounds memory access and JVM termination via crafted inputs.","title":"Out-of-Bounds Memory Access in zstd-jni","url":"https://feed.craftedsignal.io/briefs/2026-09-zstd-jni-oob-read/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:luben:zstd-jni:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.2,"id":"CVE-2026-87795"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["zstd-jni (\u003c 1.5.7-14)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","memory-safety","java"],"_cs_type":"advisory","_cs_vendors":["luben"],"content_html":"\u003cp\u003eThe zstd-jni library, which provides Java bindings for the Zstandard compression algorithm, contains a memory safety vulnerability identified as CVE-2026-87795. The flaw exists within the ZstdDictCompress constructor, where the library fails to properly validate the offset and length parameters provided during dictionary creation.\u003c/p\u003e\n\u003cp\u003eBy supplying specially crafted offset or length values to the constructor, an attacker can trigger an out-of-bounds read within the native heap. This action potentially allows sensitive memory contents to be pulled into the compression dictionary. While the primary documented outcome is a JVM crash due to memory corruption, the underlying primitive provides a mechanism for information disclosure. The vulnerability affects all versions of zstd-jni prior to 1.5.7-14. This is particularly relevant for Java applications that process untrusted data using the ZstdDictCompress functionality, as the lack of parameter validation enables an attacker to manipulate memory access patterns directly.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation leads to memory corruption, which most commonly results in a denial-of-service condition via JVM crash. However, the out-of-bounds read capability poses a significant risk of information disclosure, where sensitive data residing in the native heap may be leaked into the application's compression dictionary. Applications that handle high-privilege or sensitive data and utilize zstd-jni for compression tasks are at the highest risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the update of all Java applications utilizing the zstd-jni library to version 1.5.7-14 or later to resolve the input validation issue in CVE-2026-87795.\u003c/p\u003e\n\u003cp\u003eAudit application codebases to identify if ZstdDictCompress is invoked with parameters derived from untrusted user input, as this represents the primary attack vector for this vulnerability.\u003c/p\u003e\n","date_modified":"2026-09-09T10:50:21Z","date_published":"2026-09-09T10:50:21Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-87795/","summary":"The zstd-jni library versions prior to 1.5.7-14 are vulnerable to an out-of-bounds memory read in the ZstdDictCompress constructor, allowing local or remote attackers to read native heap memory into a compression dictionary.","title":"Out-of-Bounds Memory Read in zstd-jni","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-87795/"}],"language":"en","title":"CraftedSignal Threat Feed - Zstd-Jni (\u003c 1.5.7-14)","version":"https://jsonfeed.org/version/1.1"}