CVE-2026-90560

NameCVE-2026-90560
Descriptionzstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read vulnerability in the ZstdDictDecompress constructor because offset and length arguments are never validated against the dictionary array bounds. Attackers can supply arbitrary offset or length values to read memory past the end of the supplied array, potentially causing JVM termination.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
zstd-jni-java (PTS)bookworm1.5.2-5+ds-3vulnerable
trixie1.5.2-5+ds-7vulnerable
forky, sid1.5.2-5+ds-8vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
zstd-jni-javasource(unstable)(unfixed)

Notes

https://github.com/luben/zstd-jni/issues/405
Fixed by: https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f (v1.5.7-14)

Search for package or bug name: Reporting problems