PT-2026-95188 · Unknown · Snappy-Java
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
snappy-java versions prior to 1.1.10.9
Description
A buffer overflow exists in typed
Snappy.uncompress*Array methods. The issue occurs because output arrays are allocated by dividing the uncompressed length by the element size, but the undivided length is passed to the native code. An attacker providing malicious compressed input can cause misaligned length values, leading to writes past array bounds and corruption of heap memory.Recommendations
Update to version 1.1.10.9 or later.
Exploit
Fix
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snappy-Java