PT-2026-95189 · Unknown · Snappy-Java
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
snappy-java versions 1.1.10.8 and earlier
Description
A buffer overflow occurs in the
Snappy.compress(ByteBuffer, ByteBuffer) function when processing incompressible data that exceeds the remaining capacity of the destination buffer. This allows the process to write past the end of the buffer, leading to off-heap memory corruption and JVM termination, which can result in a Denial of Service (DoS) when untrusted data is compressed into fixed-size direct buffers.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Snappy-Java