#1148171 zstd-jni-java: CVE-2026-90852

Package:
src:zstd-jni-java
Source:
src:zstd-jni-java
Submitter:
Salvatore Bonaccorso
Date:
2026-09-17 19:37:03 UTC
Severity:
normal
Tags:
#1148171#5
Date:
2026-09-17 19:35:15 UTC
From:
To:
Hi,

The following vulnerability was published for zstd-jni-java.

CVE-2026-90852[0]:
| A vulnerability has been found in luben zstd-jni up to 1.5.7-13.
| This vulnerability affects the function ZstdCompressCtx.loadDict of
| the file ZstdCompressCtx.java of the component Dictionary Sharing.
| Such manipulation leads to use after free. The attack can be
| executed remotely. The exploit has been disclosed to the public and
| may be used. Upgrading to version 1.5.7-14 is able to resolve this
| issue. The name of the patch is
| a560131d7834598afd9cea6b7c107bc88e915936. The affected component
| should be upgraded. The vendor was contacted early, responded in a
| very professional manner and quickly released a fixed version of the
| affected product.


If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-90852
https://www.cve.org/CVERecord?id=CVE-2026-90852
[1] https://github.com/luben/zstd-jni/issues/404
[2] https://github.com/luben/zstd-jni/commit/a560131d7834598afd9cea6b7c107bc88e915936

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore