Overview
About vulnerability
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments in XXHashFactory.nativeInstance().hash32().hash(), XXHashFactory.nativeInstance().hash64().hash(), XXHashFactory.nativeInstance().newStreamingHash32().update(), and XXHashFactory.nativeInstance().newStreamingHash64().update(), allowing null arrays or oversized ranges to reach native code, read outside the Java array, and fatally terminate the JVM. This issue is fixed in version 1.11.1.Details
- Affected product:
- Apache Kafka , Apache Spark , Spring , camel , debezium , elasticsearch , lz4-java , pulsar , rabbitmq-stream-java-client , tika
- Affected packages:
- tika-detectors @ 2.9.4 (+1739 more)