CVE-2026-106451

Source
https://cve.org/CVERecord?id=CVE-2026-106451
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106451.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-106451
Aliases
  • GHSA-mcr4-qmvw-px4g
Downstream
Published
2026-10-06T19:50:41Z
Modified
2026-10-07T13:21:00Z
Severity
  • 7.3 (High) CVSS_V4 - CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user
Details

yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4.

Database specific
{
    "cna_assigner": "GitHub_M",
    "cwe_ids": [
        "CWE-367",
        "CWE-377"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/106xxx/CVE-2026-106451.json"
}
References

Affected packages

Git / github.com/yawkat/lz4-java

Affected ranges

Type
GIT
Repo
https://github.com/yawkat/lz4-java
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.11.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

1.*
1.0.0
1.2.0
1.3.0
1.4.0
1.5.0
1.6.0
1.7.0
1.8.0
v1.*
v1.10.0
v1.10.1
v1.10.2
v1.10.3
v1.10.4
v1.11.0
v1.11.1
v1.11.2
v1.11.3
v1.9.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-106451.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "214388248717931299923900274857980516335",
                "65683750676527707633078656054170255344",
                "118287103178809004985414128698616388518",
                "300637533127697537612035724601996989858",
                "266104950906479238541857316988367999351",
                "134728242984367791732063153507024217733",
                "42467283072344628588104348871426341262",
                "120304495577461616964057978192822068584",
                "241948005302004834692069803815921267754",
                "300772486054080233650511326870296722448",
                "199868925319664771762581168079999457280",
                "199852464834928763731943148423675137228",
                "5780372513503982885265799084234661786",
                "185404016909992595827221147264550945351",
                "26652769941461710058292728882523053930",
                "13075325095172813375000686650282311601",
                "269691371974919895669012905319974831748",
                "68119049062416810164251849865742483758",
                "118762952372007463797917670866819281951",
                "269126750384551754583012292750271610628",
                "173611378178514036441531353351102857178"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-106451-51af3d82",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/yawkat/lz4-java/commit/4af910bc99c2f021f0cd56f6ca7f7600f4dda4a0",
        "target": {
            "file": "src/test/net/jpountz/lz4/LZ4BlockStreamingTest.java"
        }
    },
    {
        "deprecated": false,
        "digest": {
            "function_hash": "20082239809390668882048052815584052754",
            "length": 678
        },
        "id": "CVE-2026-106451-e30894f2",
        "signature_type": "Function",
        "signature_version": "v1",
        "source": "https://github.com/yawkat/lz4-java/commit/4af910bc99c2f021f0cd56f6ca7f7600f4dda4a0",
        "target": {
            "file": "src/test/net/jpountz/lz4/LZ4BlockStreamingTest.java",
            "function": "testAvailableAfterEmptyBlock"
        }
    }
]
vanir_signatures_modified
"2026-10-07T13:21:00Z"