Search CVE reports


Toggle filters

1 – 9 of 9 results


CVE-2026-59949

Medium priority
Needs evaluation

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate the byte array object and the off and len arguments...

1 affected package

lz4-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2026-32829

Medium priority
Needs evaluation

lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from...

1 affected package

rust-lz4-flex

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
rust-lz4-flex Needs evaluation Needs evaluation Not in release — —
Show less packages

CVE-2025-66566

Medium priority
Vulnerable

yawkat LZ4 Java provides LZ4 compression for Java. Insufficient clearing of the output buffer in Java-based decompressor implementations in lz4-java 1.10.0 and earlier allows remote attackers to read previous buffer contents via...

1 affected package

lz4-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Vulnerable Vulnerable Vulnerable Vulnerable —
Show less packages

CVE-2025-12183

Medium priority
Needs evaluation

Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.

1 affected package

lz4-java

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4-java Needs evaluation Needs evaluation Needs evaluation Needs evaluation —
Show less packages

CVE-2025-62813

Medium priority
Not affected

Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

1 affected package

lz4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4 — Not affected Not affected Not affected Not affected
Show less packages

CVE-2021-3520

Medium priority
Fixed

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds...

1 affected package

lz4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4 — — Not affected Fixed Fixed
Show less packages

CVE-2019-17543

Low priority
Ignored

LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This issue can also lead to data corruption.) NOTE: the...

1 affected package

lz4

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
lz4 — — Not affected Not affected Not affected
Show less packages

CVE-2014-4715

Medium priority

Some fixes available 1 of 56

Yann Collet LZ4 before r119, when used on certain 32-bit platforms that allocate memory beyond 0x80000000, does not properly detect integer overflows, which allows context-dependent attackers to cause a denial of service (memory...

10 affected packages

eet, efl, firefox, grub2, gtkwave...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
eet — — Not in release Not in release Not in release
efl — — Not affected Not affected Not affected
firefox — — Not affected Not in release Not affected
grub2 — — Not affected Not affected Not affected
gtkwave — — Not affected Not affected Not affected
lz4 — — Not affected Not affected Not affected
php-horde-lz4 — — Not in release Not in release Not affected
pytables — — Not affected Not affected Not affected
thunderbird — — Not affected Not in release Not affected
zfsutils — — Not in release Not in release Not in release
Show all 10 packages Show less packages

CVE-2014-4611

Medium priority

Some fixes available 5 of 13

Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow...

74 affected packages

linux, linux-aws, linux-aws-5.0, linux-aws-5.11, linux-aws-5.3...

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
linux — — — Not affected Not affected
linux-aws — — — Not affected Not affected
linux-aws-5.0 — — — Not in release Not affected
linux-aws-5.11 — — — Not affected Not in release
linux-aws-5.3 — — — Not in release Not affected
linux-aws-5.4 — — — Not in release Not affected
linux-aws-5.8 — — — Not affected Not in release
linux-aws-hwe — — — Not in release Not in release
linux-azure — — — Not affected Not affected
linux-azure-4.15 — — — Not in release Not affected
linux-azure-5.11 — — — Not affected Not in release
linux-azure-5.3 — — — Not in release Not affected
linux-azure-5.4 — — — Not in release Not affected
linux-azure-5.8 — — — Not affected Not in release
linux-azure-edge — — — Not in release Not affected
linux-bluefield — — — Not affected Not in release
linux-dell300x — — — Not in release Not affected
linux-ec2 — — — Not in release Not in release
linux-euclid — — — Not in release Not in release
linux-flo — — — Not in release Not in release
linux-fsl-imx51 — — — Not in release Not in release
linux-gcp — — — Not affected Not affected
linux-gcp-4.15 — — — Not in release Not affected
linux-gcp-5.3 — — — Not in release Not affected
linux-gcp-5.4 — — — Not in release Not affected
linux-gcp-5.8 — — — Not affected Not in release
linux-gcp-edge — — — Not in release Not affected
linux-gke — — — Not affected Not in release
linux-gke-4.15 — — — Not in release Not affected
linux-gke-5.0 — — — Not in release Not affected
linux-gke-5.3 — — — Not in release Not affected
linux-gke-5.4 — — — Not in release Not affected
linux-gkeop — — — Not affected Not in release
linux-gkeop-5.4 — — — Not in release Not affected
linux-goldfish — — — Not in release Not in release
linux-grouper — — — Not in release Not in release
linux-hwe — — — Not in release Not affected
linux-hwe-5.11 — — — Not affected Not in release
linux-hwe-5.4 — — — Not in release Not affected
linux-hwe-5.8 — — — Not affected Not in release
linux-hwe-edge — — — Not in release Not affected
linux-kvm — — — Not affected Not affected
linux-lts-quantal — — — Not in release Not in release
linux-lts-raring — — — Not in release Not in release
linux-lts-saucy — — — Not in release Not in release
linux-lts-trusty — — — Not in release Not in release
linux-lts-utopic — — — Not in release Not in release
linux-lts-vivid — — — Not in release Not in release
linux-lts-wily — — — Not in release Not in release
linux-lts-xenial — — — Not in release Not in release
linux-maguro — — — Not in release Not in release
linux-mako — — — Not in release Not in release
linux-manta — — — Not in release Not in release
linux-mvl-dove — — — Not in release Not in release
linux-oem — — — Not in release Not affected
linux-oem-5.10 — — — Not affected Not in release
linux-oem-5.13 — — — Not affected Not in release
linux-oem-5.6 — — — Not affected Not in release
linux-oem-osp1 — — — Not in release Not affected
linux-oracle — — — Not affected Not affected
linux-oracle-5.0 — — — Not in release Not affected
linux-oracle-5.11 — — — Not affected Not in release
linux-oracle-5.3 — — — Not in release Not affected
linux-oracle-5.4 — — — Not in release Not affected
linux-oracle-5.8 — — — Not affected Not in release
linux-raspi — — — Not affected Not in release
linux-raspi-5.4 — — — Not in release Not affected
linux-raspi2 — — — Not affected Not affected
linux-raspi2-5.3 — — — Not in release Not affected
linux-riscv — — — Not affected Not in release
linux-riscv-5.11 — — — Not affected Not in release
linux-riscv-5.8 — — — Not affected Not in release
linux-snapdragon — — — Not in release Not affected
lz4 — — — Not affected Not affected
Show all 74 packages Show less packages