Bug 2533570 - CVE-2026-90852 python-avro: luben zstd-jni: Remote use-after-free vulnerability in dictionary sharing [fedora-all]
Summary: CVE-2026-90852 python-avro: luben zstd-jni: Remote use-after-free vulnerabili...
Keywords:
Status: NEW
Alias: None
Product: Fedora
Classification: Fedora
Component: python-avro
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: dev
QA Contact:
URL:
Whiteboard: {"flaws": ["28591e36-125d-42d6-a83d-4...
Depends On:
Blocks: CVE-2026-90852
TreeView+ depends on / blocked
 
Reported: 2026-09-15 03:35 UTC by Ganesh
Modified: 2026-09-15 03:35 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Ganesh 2026-09-15 03:35:26 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This vulnerability affects the function ZstdCompressCtx.loadDict of the file ZstdCompressCtx.java of the component Dictionary Sharing. Such manipulation leads to use after free. The attack can be executed remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 1.5.7-14 is able to resolve this issue. The name of the patch is a560131d7834598afd9cea6b7c107bc88e915936. The affected component should be upgraded. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.


Note You need to log in before you can comment on or make changes to this bug.