{"id":"openSUSE-SU-2026:21902-1","summary":"Security update for zstd-jni","details":"This update for zstd-jni fixes the following issues:\n\n- CVE-2026-87823: denial of Service or Information Disclosure via out-of-bounds read (bsc#1279953).\n- CVE-2026-87824: denial of Service (DoS) via out-of-bounds read in Zstd.trainFromBufferDirect (bsc#1279956).\n- CVE-2026-87825: use-after-free resulting in silent data corruption or JVM crashes (bsc#1279955).\n- CVE-2026-87877: use-After-Free vulnerability allows memory corruption and denial of service (bsc#1279954).\n\nChanges for zstd-jni:\n\n- update to version v1.5.7.16.\n","modified":"2026-09-25T18:23:12.440162389Z","published":"2026-09-21T17:44:10Z","related":["CVE-2026-87823","CVE-2026-87824","CVE-2026-87825","CVE-2026-87877"],"upstream":["CVE-2026-87823","CVE-2026-87824","CVE-2026-87825","CVE-2026-87877"],"references":[{"type":"ADVISORY"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279953"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279954"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279955"},{"type":"REPORT","url":"https://bugzilla.suse.com/1279956"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-87823"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-87824"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-87825"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-87877"}],"affected":[{"package":{"name":"zstd-jni","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/zstd-jni&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.5.7.16-160000.1.1"}]}],"ecosystem_specific":{"binaries":[{"zstd-jni":"1.5.7.16-160000.1.1","zstd-jni-javadoc":"1.5.7.16-160000.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21902-1.json"}}],"schema_version":"1.9.0"}