<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Lz4 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/lz4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Wed, 07 Oct 2026 22:48:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/lz4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Race Condition Vulnerability in lz4-java Native Library Extraction</title><link>https://feed.craftedsignal.io/briefs/2026-10-yawkat-lz4-race-condition/</link><pubDate>Wed, 07 Oct 2026 22:48:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-yawkat-lz4-race-condition/</guid><description>The lz4-java library is vulnerable to a race condition during native library extraction that allows a local user to perform arbitrary code execution or a denial of service.</description><content:encoded><![CDATA[<p>The yawkat and lz4 lz4-java libraries are vulnerable to a race condition in the <code>net.jpountz.util.Native.load()</code> method. When the library fails to find a system-installed native component, it extracts a bundled native JNI library to <code>java.io.tmpdir</code>. The library uses a predictable file path for the extraction, which is created using <code>FileOutputStream</code> without exclusive file creation flags. This allows a local attacker with write access to the same temporary directory to pre-create or symlink the file before the library extraction process completes.</p>
<p>If successful, the attacker can replace the intended native library with malicious code, which is then loaded by the victim's JVM via <code>System.load()</code>, executing with the victim's privileges. The vulnerability depends on host-level protections; systems with <code>fs.protected_regular</code> or <code>fs.protected_symlinks</code> enabled may mitigate the code execution vector but remain susceptible to a denial of service if the library fails to load. This vulnerability impacts lz4-java versions 1.7.0 through 1.8.1 and 1.11.3 and earlier.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows a local attacker to execute arbitrary code within the context of the vulnerable Java application. In environments where OS-level protections (such as hardened symlink or file creation settings) are disabled, or in shared temporary directories without sticky bits (including certain container configurations), the risk of privilege escalation is significant. If exploitation is prevented by OS protections, attackers can still trigger a denial of service by causing the library loading process to fail, forcing the application to fall back to less performant Java implementations or crash.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Patch immediately by upgrading to lz4-java version 1.11.4 or later, which utilizes secure temporary file creation.</li>
<li>For applications where patching is not immediately feasible, configure the application to run with a dedicated, private <code>java.io.tmpdir</code> that is restricted to the application service user.</li>
<li>Alternatively, install the native <code>liblz4-java</code> package at the OS level and ensure it is available on the <code>java.library.path</code>, which bypasses the insecure extraction logic entirely.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>local-exploitation</category><category>privilege-escalation</category></item></channel></rss>