{"id":"CVE-2026-87824","summary":"zstd-jni 1.3.3-1 through 1.5.7-13 Out-of-Bounds Read via Zstd.trainFromBufferDirect","details":"zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity in Zstd.trainFromBufferDirect, allowing attackers to read past buffer boundaries by supplying oversized per-sample lengths. Attackers can trigger out-of-bounds memory access by providing crafted sample length arrays that cause the native implementation to walk past the buffer allocation, resulting in JVM termination.","aliases":["GHSA-257p-3h6w-pg7h"],"modified":"2026-09-10T08:16:10.299186Z","published":"2026-09-09T14:32:44.099Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-125"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87824.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/87xxx/CVE-2026-87824.json"},{"type":"PACKAGE","url":"https://github.com/luben/zstd-jni"},{"type":"ARTICLE","url":"https://github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/java/com/github/luben/zstd/Zstd.java"},{"type":"ARTICLE","url":"https://github.com/luben/zstd-jni/blob/v1.5.7-13/src/main/native/jni_zdict.c"},{"type":"FIX","url":"https://github.com/luben/zstd-jni/commit/53d3c6342883f7d6717b2477a7f9c1b4a4a56980"},{"type":"FIX","url":"https://github.com/luben/zstd-jni/commit/bba6cfca2c0897f1fa004f4193247479f10da853"},{"type":"ADVISORY","url":"https://github.com/luben/zstd-jni/releases/tag/v1.5.7-14"},{"type":"ADVISORY","url":"https://github.com/luben/zstd-jni/security/advisories/GHSA-257p-3h6w-pg7h"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-87824"},{"type":"WEB","url":"https://repo1.maven.org/maven2/com/github/luben/zstd-jni/"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/zstd-jni-1.3.3-1-through-1.5.7-13-out-of-bounds-read-via-zstd-trainfrombufferdirect"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/luben/zstd-jni","events":[{"introduced":"b7a712fa9c3f06a82b627ab8133a56fa96667f55"},{"fixed":"3216860eea289fbbae0b191c0a4fd8b72dad949c"}],"database_specific":{"extracted_events":[{"introduced":"1.3.3-1"},{"fixed":"1.5.7-14"}],"source":"AFFECTED_FIELD"}}],"versions":["v1.5.7-13","v1.5.7-12","v1.5.7-11","v1.5.7-9","v1.5.7-8","v1.5.7-7","v1.5.7-6","v1.5.7-5","v1.5.7-4","v1.5.7-3","v1.5.7-2","v1.5.7-1","v1.5.6-10","v1.5.6-9","v1.5.6-8","v1.5.6-7","v1.5.6-6","v1.5.6-5","v1.5.6-4","v1.5.6-3","v1.5.6-2","v1.5.6-1","v1.5.5-11","v1.5.5-10","v1.5.5-9","b1.5.5-9","v1.5.5-8","v1.5.5-7","v1.5.5-6","v.1.5.5-5","v1.5.5-3","v1.5.5-2","v1.5.5-1","v1.5.4-2","v1.5.4-1","c1.5.2-5","v1.5.2-3","v1.5.2-2","v1.5.2-1","v1.5.1-1","v1.5.0-5","v1.5.0-4","v1.5.0-3","v1.5.0-2","v1.5.0-1","v1.4.9-5","v1.4.9-4","v1.4.9-3","v1.4.9-2","v1.4.9-1","v1.4.8-7","v1.4.8-6","v1.4.8-5","v1.4.8-4","v1.4.8-3","v1.4.8-2","v1.4.8-1","v1.4.7-3","v1.4.7-2","v1.4.7-1","v1.4.5-12","v1.4.5-11","v1.4.5-10","v1.4.5-9","v1.4.5-8","v1.4.5-7","v1.4.5-6","v1.4.5-4","v1.4.5-3","v1.4.5-2","v1.4.5-1","v1.4.4-11","v1.4.4-10","v1.4.4-9","v1.4.4-8","v1.4.4-7","v1.4.4-5","1.4.4-4","v1.4.4-3","v1.4.4-2","v1.4.3-1","v1.4.2-1","v1.4.1-1","v1.4.0-1","v.1.3.8-9","v1.3.8-8","v1.3.8-7","v1.3.8-6","v1.3.8-5","v1.3.8-4","v1.3.8-3","v1.3.8-2","v1.3.8-1","v1.3.7-3","v1.3.7-2","v1.3.7-1","v1.3.6-1","v1.3.5-3","v1.3.5-2","v1.3.5-1","v1.3.4-10","v1.3.4-8","v1.3.4-1","v1.3.3-1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-87824.json","vanir_signatures_modified":"2026-09-10T08:16:10Z","vanir_signatures":[{"id":"CVE-2026-87824-44dbbae1","signature_type":"Function","signature_version":"v1","source":"https://github.com/luben/zstd-jni/commit/3216860eea289fbbae0b191c0a4fd8b72dad949c","target":{"file":"src/main/native/jni_zstd.c","function":"Java_com_github_luben_zstd_Zstd_getDirectByteBufferFrameContentSize"},"deprecated":false,"digest":{"function_hash":"319696483832917712384682231278816072707","length":525}},{"deprecated":false,"digest":{"line_hashes":["242983979289756636978174893894911169283","157823411836278810979700492519583258858","47982388172284482667079231190836641912","142002538935986523140505977783435642687","70654406038950244899492554068964697791","256841266079176367404669460587415964017","136130365917502750732790875301653462261","307914870517560413069750160813139035083","70654406038950244899492554068964697791","256841266079176367404669460587415964017","136130365917502750732790875301653462261","307914870517560413069750160813139035083"],"threshold":0.9},"id":"CVE-2026-87824-cf1cd55a","signature_type":"Line","signature_version":"v1","source":"https://github.com/luben/zstd-jni/commit/3216860eea289fbbae0b191c0a4fd8b72dad949c","target":{"file":"src/main/native/jni_zstd.c"}},{"signature_version":"v1","source":"https://github.com/luben/zstd-jni/commit/3216860eea289fbbae0b191c0a4fd8b72dad949c","target":{"file":"src/main/native/jni_zstd.c","function":"Java_com_github_luben_zstd_Zstd_findDirectByteBufferFrameCompressedSize"},"deprecated":false,"digest":{"function_hash":"6130561471615133004258603361745015963","length":503},"id":"CVE-2026-87824-e402cad3","signature_type":"Function"},{"signature_version":"v1","source":"https://github.com/luben/zstd-jni/commit/3216860eea289fbbae0b191c0a4fd8b72dad949c","target":{"file":"src/main/native/jni_zstd.c","function":"Java_com_github_luben_zstd_Zstd_decompressedDirectByteBufferSize"},"deprecated":false,"digest":{"function_hash":"243452810049814927721413726162029308560","length":552},"id":"CVE-2026-87824-e43e017d","signature_type":"Function"}]}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}