CVE-2026-106451

NameCVE-2026-106451
Descriptionyawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1150247

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lz4-java (PTS)bookworm1.8.0-3vulnerable
trixie1.8.0-4vulnerable
forky, sid1.11.2+ds1-3vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lz4-javasource(unstable)(unfixed)1150247

Notes

https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g
Fixed by: https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3 (v1.11.4)

Search for package or bug name: Reporting problems