Bug 2547101 (CVE-2026-106449)

Summary: CVE-2026-106449 org.lz4/lz4-java: lz4-java: Denial of Service via stack exhaustion from empty blocks
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: low Docs Contact:
Priority: low    
Version: unspecifiedCC: anujha, asoldano, bbaranow, bmaxwell, bstansbe, ccranfor, dlofthou, fmariani, gmalinko, istudens, ivassile, iweiss, janstey, jpechane, jwon, kaycoth, mcarlett, mosmerov, msvehla, nwallace, pberan, pdelbell, pesilva, pjindal, pmackay, rhel-process-autobot, rstancel, rstepani, tcunning, thjenkin, vdosoudi, watson-tool-maintainers, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in lz4-java. This issue can lead to a Denial of Service (DoS) when the LZ4 input stream is configured not to stop upon encountering empty blocks. In this non-default configuration, consecutive empty blocks are processed via recursive calls rather than iterative handling. A remote attacker can exploit this vulnerability by supplying a crafted compressed stream containing a long sequence of empty blocks, exhausting the thread's memory stack and causing the application to crash.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-10-06 19:52:19 UTC
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.