Source: lz4
Version: 1.10.0-4
Severity: important
Tags: security upstream
Forwarded: https://github.com/lz4/lz4/pull/1593
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerability was published for lz4.

CVE-2025-62813[0]:
| LZ4 through 1.10.0 allows attackers to cause a denial of service
| (application crash) or possibly have unspecified other impact when
| the application processes untrusted LZ4 frames. For example,
| LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-62813
    https://www.cve.org/CVERecord?id=CVE-2025-62813
[1] https://github.com/lz4/lz4/pull/1593
[2] https://github.com/lz4/lz4/commit/f64efec011c058bd70348576438abac222fe6c82

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to