CVE-2026-106449

NameCVE-2026-106449
Descriptionyawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1150247

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lz4-java (PTS)bookworm1.8.0-3vulnerable
trixie1.8.0-4vulnerable
forky, sid1.11.2+ds1-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lz4-javasource(unstable)(unfixed)1150247

Notes

https://github.com/yawkat/lz4-java/security/advisories/GHSA-343h-94h5-c4wr
Fixed by: https://github.com/yawkat/lz4-java/commit/c8ebf97d504fb34434fda46fc761e8202570e0d8 (v1.11.4)

Search for package or bug name: Reporting problems