Source: zstd-jni-java Version: 1.5.2-5+ds-8 Severity: important Tags: security upstream Forwarded: https://github.com/luben/zstd-jni/issues/404 X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi, The following vulnerability was published for zstd-jni-java. CVE-2026-90852[0]: | A vulnerability has been found in luben zstd-jni up to 1.5.7-13. | This vulnerability affects the function ZstdCompressCtx.loadDict of | the file ZstdCompressCtx.java of the component Dictionary Sharing. | Such manipulation leads to use after free. The attack can be | executed remotely. The exploit has been disclosed to the public and | may be used. Upgrading to version 1.5.7-14 is able to resolve this | issue. The name of the patch is | a560131d7834598afd9cea6b7c107bc88e915936. The affected component | should be upgraded. The vendor was contacted early, responded in a | very professional manner and quickly released a fixed version of the | affected product. If you fix the vulnerability please also make sure to include the CVE (Common Vulnerabilities & Exposures) id in your changelog entry. For further information see: [0] https://security-tracker.debian.org/tracker/CVE-2026-90852 https://www.cve.org/CVERecord?id=CVE-2026-90852 [1] https://github.com/luben/zstd-jni/issues/404 [2] https://github.com/luben/zstd-jni/commit/a560131d7834598afd9cea6b7c107bc88e915936 Please adjust the affected versions in the BTS as needed. Regards, Salvatore

