Bug 2531003 (CVE-2026-87877)

Summary: CVE-2026-87877 com.github.luben/zstd-jni: zstd-jni: Use-After-Free vulnerability allows memory corruption and denial of service
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security <prodsec-ir-bot>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: amctagga, ant, anujha, aoconnor, asoldano, asyoung, avibelli, bbaranow, bgeorges, bmaxwell, bniver, bstansbe, ccranfor, cescoffi, cmah, dandread, dkreling, dlofthou, ewittman, flucifre, fmariani, fmongiar, gmalinko, gmeno, groman, gsmet, gtanzill, istudens, ivassile, iweiss, janstey, jbuscemi, jhollowa, jmartisk, jnethert, jpechane, jwon, kaycoth, lthon, manderse, mbenjamin, mcarlett, mhackett, mosmerov, msvehla, nipatil, nwallace, olubyans, pantinor, pberan, pdelbell, pesilva, pgallagh, pjindal, pmackay, prichard, probinso, rguimara, rhel-process-autobot, rkubis, rruss, rstancel, rstepani, rsvoboda, sbiarozk, sostapov, sthirugn, tcunning, thjenkin, tqvarnst, vdosoudi, vereddy, watson-tool-maintainers, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in zstd-jni. An attacker could exploit a use-after-free vulnerability by calling specific methods on closed streams without proper validation. This could lead to memory corruption, potentially allowing the attacker to corrupt unrelated objects or cause the Java Virtual Machine (JVM) to crash, resulting in a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2531333, 2531334, 2531335, 2531336    
Bug Blocks:    

Description OSIDB Bzimport 2026-09-09 14:52:45 UTC
zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.

Comment 2 Jon Orris 2026-09-22 14:02:05 UTC
This issue has been addressed in the following products:

  Red Hat Build of Apache Camel 3.33 for Quarkus 3.33.3.SP2

Via RHSA-2026:70257 https://access.redhat.com/errata/RHSA-2026:70257

Comment 3 Jon Orris 2026-09-24 19:58:01 UTC
This issue has been addressed in the following products:

  Red Hat build of Apache Camel 4.18.4 for Spring Boot 3.5.16

Via RHSA-2026:71675 https://access.redhat.com/errata/RHSA-2026:71675