PT-2026-89055 · Git+2 · Zstd-Jni

CVE-2026-87825

·

Publicado

2026-08-16

·

Atualizado

2026-09-09

CVSS v3.1

7.7

Alta

VetorAV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where streams and contexts hold a dictionary's shared lock only during the load call, allowing the dictionary to be closed while still referenced. Attackers can close a dictionary after associating it with a stream or context, causing subsequent read or write operations to access freed native memory, resulting in silent data corruption or JVM crashes.

Exploit

Correção

Use After Free

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2026-14469
CVE-2026-87825
GHSA-947W-PXJJ-C7M9

Produtos afetados

Zstd-Jni