DEBIAN-CVE-2026-106449

Source
https://security-tracker.debian.org/tracker/CVE-2026-106449
Import Source
https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-106449.json
JSON Data
https://api.osv.dev/v1/vulns/DEBIAN-CVE-2026-106449
Upstream
Published
2026-10-06T20:17:26Z
Modified
2026-10-07T11:00:08Z
Severity
  • 3.7 (Low) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:L CVSS Calculator
Summary
[none]
Details

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.4, net.jpountz.lz4.LZ4BlockInputStream configured with stopOnEmptyBlock set to false handles each well-formed empty LZ4Block by recursively calling refill(), allowing a long sequence of empty blocks in an attacker-controlled compressed stream to exhaust the decoding thread's stack and throw StackOverflowError. The default stopOnEmptyBlock setting is true and is not affected, and the issue does not cause memory corruption. This issue is fixed in version 1.11.4.

References

Affected packages

Debian:12 / lz4-java

Package

Name
lz4-java
Purl
pkg:deb/debian/lz4-java?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.8.0-3
1.8.0-4
1.11.2+ds1-1
1.11.2+ds1-2
1.11.2+ds1-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-106449.json"

Debian:13 / lz4-java

Package

Name
lz4-java
Purl
pkg:deb/debian/lz4-java?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.8.0-4
1.11.2+ds1-1
1.11.2+ds1-2
1.11.2+ds1-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-106449.json"

Debian:14 / lz4-java

Package

Name
lz4-java
Purl
pkg:deb/debian/lz4-java?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected

Affected versions

1.*
1.8.0-4
1.11.2+ds1-1
1.11.2+ds1-2
1.11.2+ds1-3

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/debian-osv/debian-cve-osv/DEBIAN-CVE-2026-106449.json"