Bug 2547136 (CVE-2026-106452)

Summary: CVE-2026-106452 org.lz4/lz4-java: lz4-java: Denial of Service via excessive memory allocation
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: medium Docs Contact:
Priority: medium    
Version: unspecifiedCC: anujha, asoldano, bbaranow, bmaxwell, bstansbe, ccranfor, dlofthou, fmariani, gmalinko, istudens, ivassile, iweiss, janstey, jpechane, jwon, kaycoth, mcarlett, mosmerov, msvehla, nwallace, pberan, pdelbell, pesilva, pjindal, pmackay, rhel-process-autobot, rstancel, rstepani, tcunning, thjenkin, vdosoudi, watson-tool-maintainers, yfang
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in lz4-java. A remote attacker can trigger a Denial of Service (DoS) by providing a crafted compressed data stream with an oversized block header. During decompression, the input stream allocates memory based on this attacker-controlled size field before reading the actual payload, which can exhaust available Java Virtual Machine (JVM) memory and crash the application.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:

Description OSIDB Bzimport 2026-10-06 20:02:36 UTC
yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.2, net.jpountz.lz4.LZ4BlockInputStream refill() validates that the compressedLen field in a legacy LZ4Block header is nonnegative but allocates a compressed-input buffer of that attacker-controlled size before reading payload data, allowing a header-only stream to request a near-2 GiB allocation and exhaust the JVM heap. Canonical writers emit raw blocks when compression is not smaller than the original block, but vulnerable readers accept non-canonical oversized compressed blocks. This issue is fixed in version 1.11.2.