| Name | CVE-2026-87877 |
| Description | zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM. |
| Source | CVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more) |
| Debian Bugs | 1147397 |
The table below lists information on source packages.
| Source Package | Release | Version | Status |
|---|---|---|---|
| zstd-jni-java (PTS) | bookworm | 1.5.2-5+ds-3 | vulnerable |
| trixie | 1.5.2-5+ds-7 | vulnerable | |
| forky, sid | 1.5.2-5+ds-8 | vulnerable |
The information below is based on the following data on fixed versions.
| Package | Type | Release | Fixed Version | Urgency | Origin | Debian Bugs |
|---|---|---|---|---|---|---|
| zstd-jni-java | source | (unstable) | (unfixed) | 1147397 |
[trixie] - zstd-jni-java <no-dsa> (Minor issue)
[bookworm] - zstd-jni-java <postponed> (Minor issue)
https://github.com/luben/zstd-jni/security/advisories/GHSA-2jw3-mg7f-vw4q
Fixed by: https://github.com/luben/zstd-jni/commit/f38f9a1563113d96d0fc38baee543f7457dd8a8e (v1.5.7-14)
Fixed by: https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555 (v1.5.7-14)