PT-2025-43426 · Lz4 · Lz4

Published

2025-10-23

·

Updated

2025-10-30

·

CVE-2025-62813

CVSS v3.1

5.9

Medium

VectorAV:L/AC:H/PR:N/UI:N/S:C/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions LZ4 versions through 1.10.0
Description LZ4 through version 1.10.0 contains a flaw that could allow attackers to cause a denial of service (application crash) or potentially achieve other unspecified impacts when processing untrusted LZ4 frames. Specifically, the LZ4F createCDict advanced function in lib/lz4frame.c does not properly handle NULL checks.
Recommendations Update to a version of LZ4 newer than 1.10.0.

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-62813
ECHO-7C08-CB6B-2953
OPENSUSE-SU-2025:15675-1
OPENSUSE-SU-2025:15678-1
OPENSUSE-SU-2025:15679-1
OPENSUSE-SU-2025:15688-1

Affected Products

Lz4