VYPR
High severity8.2NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026

CVE-2026-87823

CVE-2026-87823

Description

zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three direct-ByteBuffer frame-size native methods, allowing out-of-bounds memory reads via negative or overflowing offsets. Attackers can supply negative offset values near Integer.MIN_VALUE to read unmapped memory, causing JVM termination or extracting arbitrary frame size data from unintended memory locations.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Luben/Zstd Jnireferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: <1.5.7-14

Patches

Vulnerability mechanics

References

7

News mentions

0

No linked articles in our index yet.