{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/lz4/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-106451"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["lz4-java (\u003c= 1.11.3)","lz4-java (\u003e= 1.7.0, \u003c= 1.8.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","local-exploitation","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["yawkat","lz4"],"content_html":"\u003cp\u003eThe yawkat and lz4 lz4-java libraries are vulnerable to a race condition in the \u003ccode\u003enet.jpountz.util.Native.load()\u003c/code\u003e method. When the library fails to find a system-installed native component, it extracts a bundled native JNI library to \u003ccode\u003ejava.io.tmpdir\u003c/code\u003e. The library uses a predictable file path for the extraction, which is created using \u003ccode\u003eFileOutputStream\u003c/code\u003e without exclusive file creation flags. This allows a local attacker with write access to the same temporary directory to pre-create or symlink the file before the library extraction process completes.\u003c/p\u003e\n\u003cp\u003eIf successful, the attacker can replace the intended native library with malicious code, which is then loaded by the victim's JVM via \u003ccode\u003eSystem.load()\u003c/code\u003e, executing with the victim's privileges. The vulnerability depends on host-level protections; systems with \u003ccode\u003efs.protected_regular\u003c/code\u003e or \u003ccode\u003efs.protected_symlinks\u003c/code\u003e enabled may mitigate the code execution vector but remain susceptible to a denial of service if the library fails to load. This vulnerability impacts lz4-java versions 1.7.0 through 1.8.1 and 1.11.3 and earlier.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local attacker to execute arbitrary code within the context of the vulnerable Java application. In environments where OS-level protections (such as hardened symlink or file creation settings) are disabled, or in shared temporary directories without sticky bits (including certain container configurations), the risk of privilege escalation is significant. If exploitation is prevented by OS protections, attackers can still trigger a denial of service by causing the library loading process to fail, forcing the application to fall back to less performant Java implementations or crash.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003ePatch immediately by upgrading to lz4-java version 1.11.4 or later, which utilizes secure temporary file creation.\u003c/li\u003e\n\u003cli\u003eFor applications where patching is not immediately feasible, configure the application to run with a dedicated, private \u003ccode\u003ejava.io.tmpdir\u003c/code\u003e that is restricted to the application service user.\u003c/li\u003e\n\u003cli\u003eAlternatively, install the native \u003ccode\u003eliblz4-java\u003c/code\u003e package at the OS level and ensure it is available on the \u003ccode\u003ejava.library.path\u003c/code\u003e, which bypasses the insecure extraction logic entirely.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-07T22:48:42Z","date_published":"2026-10-07T22:48:42Z","id":"https://feed.craftedsignal.io/briefs/2026-10-yawkat-lz4-race-condition/","summary":"The lz4-java library is vulnerable to a race condition during native library extraction that allows a local user to perform arbitrary code execution or a denial of service.","title":"Race Condition Vulnerability in lz4-java Native Library Extraction","url":"https://feed.craftedsignal.io/briefs/2026-10-yawkat-lz4-race-condition/"}],"language":"en","title":"CraftedSignal Threat Feed - Lz4","version":"https://jsonfeed.org/version/1.1"}