{"id":"UBUNTU-CVE-2025-62813","details":"LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.","modified":"2025-10-27T08:32:45.494712Z","published":"2025-10-24T00:00:00Z","withdrawn":"2025-10-30T05:25:20Z","upstream":["CVE-2025-62813"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2025-62813"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2025-62813"},{"type":"REPORT","url":"https://github.com/lz4/lz4/pull/1593"},{"type":"REPORT","url":"https://github.com/lz4/lz4/commit/f64efec011c058bd70348576438abac222fe6c82"}],"affected":[{"package":{"name":"lz4","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/lz4@0.0~r114-2ubuntu1+esm2?arch=source&distro=esm-infra-legacy/trusty"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0~r94-2","0.0~r99-1","0.0~r107-1","0.0~r109-1","0.0~r114-2ubuntu1","0.0~r114-2ubuntu1+esm1","0.0~r114-2ubuntu1+esm2"],"ecosystem_specific":{"binaries":[{"binary_name":"liblz4-1","binary_version":"0.0~r114-2ubuntu1+esm2"},{"binary_name":"liblz4-dev","binary_version":"0.0~r114-2ubuntu1+esm2"},{"binary_name":"liblz4-tool","binary_version":"0.0~r114-2ubuntu1+esm2"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62813.json"}},{"package":{"name":"lz4","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/lz4@0.0~r131-2ubuntu2+esm1?arch=source&distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0~r131-1","0.0~r131-2","0.0~r131-2ubuntu2","0.0~r131-2ubuntu2+esm1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblz4-1","binary_version":"0.0~r131-2ubuntu2+esm1"},{"binary_name":"liblz4-dev","binary_version":"0.0~r131-2ubuntu2+esm1"},{"binary_name":"liblz4-tool","binary_version":"0.0~r131-2ubuntu2+esm1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62813.json"}},{"package":{"name":"lz4","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/lz4@0.0~r131-2ubuntu3.1?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["0.0~r131-2ubuntu2","0.0~r131-2ubuntu3","0.0~r131-2ubuntu3.1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblz4-1","binary_version":"0.0~r131-2ubuntu3.1"},{"binary_name":"liblz4-dev","binary_version":"0.0~r131-2ubuntu3.1"},{"binary_name":"liblz4-tool","binary_version":"0.0~r131-2ubuntu3.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62813.json"}},{"package":{"name":"lz4","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/lz4@1.9.2-2ubuntu0.20.04.1?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.1-1","1.9.1-2","1.9.2-2","1.9.2-2ubuntu0.20.04.1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblz4-1","binary_version":"1.9.2-2ubuntu0.20.04.1"},{"binary_name":"liblz4-dev","binary_version":"1.9.2-2ubuntu0.20.04.1"},{"binary_version":"1.9.2-2ubuntu0.20.04.1","binary_name":"liblz4-tool"},{"binary_name":"lz4","binary_version":"1.9.2-2ubuntu0.20.04.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62813.json"}},{"package":{"name":"lz4","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/lz4@1.9.3-2build2?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.3-2","1.9.3-2build1","1.9.3-2build2"],"ecosystem_specific":{"binaries":[{"binary_name":"liblz4-1","binary_version":"1.9.3-2build2"},{"binary_name":"liblz4-dev","binary_version":"1.9.3-2build2"},{"binary_name":"liblz4-tool","binary_version":"1.9.3-2build2"},{"binary_version":"1.9.3-2build2","binary_name":"lz4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62813.json"}},{"package":{"name":"lz4","ecosystem":"Ubuntu:24.04:LTS","purl":"pkg:deb/ubuntu/lz4@1.9.4-1build1.1?arch=source&distro=noble"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.4-1","1.9.4-1build1","1.9.4-1build1.1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblz4-1","binary_version":"1.9.4-1build1.1"},{"binary_name":"liblz4-dev","binary_version":"1.9.4-1build1.1"},{"binary_name":"liblz4-tool","binary_version":"1.9.4-1build1.1"},{"binary_name":"lz4","binary_version":"1.9.4-1build1.1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62813.json"}},{"package":{"name":"lz4","ecosystem":"Ubuntu:25.10","purl":"pkg:deb/ubuntu/lz4@1.10.0-4build1?arch=source&distro=questing"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.10.0-4","1.10.0-4build1"],"ecosystem_specific":{"binaries":[{"binary_name":"liblz4-1","binary_version":"1.10.0-4build1"},{"binary_name":"liblz4-dev","binary_version":"1.10.0-4build1"},{"binary_version":"1.10.0-4build1","binary_name":"lz4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62813.json"}},{"package":{"name":"lz4","ecosystem":"Ubuntu:25.04","purl":"pkg:deb/ubuntu/lz4@1.10.0-4?arch=source&distro=plucky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.9.4-3","1.9.4-4","1.10.0-3","1.10.0-4"],"ecosystem_specific":{"binaries":[{"binary_name":"liblz4-1","binary_version":"1.10.0-4"},{"binary_name":"liblz4-dev","binary_version":"1.10.0-4"},{"binary_name":"lz4","binary_version":"1.10.0-4"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2025/UBUNTU-CVE-2025-62813.json"}}],"schema_version":"1.7.3","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}