High severity7.7NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-87877
CVE-2026-87877
Description
zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
8- github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/BaseZstdBufferDecompressingStreamNoFinalizer.javanvd
- github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/ZstdInputStreamNoFinalizer.javanvd
- github.com/luben/zstd-jni/commit/0827ed02551bbd8d6f8e4bbff99d83bf50f91938nvd
- github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555nvd
- github.com/luben/zstd-jni/commit/f38f9a1563113d96d0fc38baee543f7457dd8a8envd
- github.com/luben/zstd-jni/releases/tag/v1.5.7-14nvd
- github.com/luben/zstd-jni/security/advisories/GHSA-2jw3-mg7f-vw4qnvd
- www.vulncheck.com/advisories/zstd-jni-1.3.8-4-through-1.5.7-13-use-after-free-via-setters-called-after-closenvd
News mentions
0No linked articles in our index yet.