PT-2025-48344 · Lz4-Java+1 · Lz4-Java+1

Jonas Konrad

+1

·

Published

2025-11-26

·

Updated

2026-05-18

·

CVE-2025-12183

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions org.lz4:lz4-java versions prior to 1.8.0
Description The software contains flaws related to memory handling. Specifically, out-of-bounds memory operations can occur when processing untrusted compressed input. This can lead to a denial of service and potential reading of adjacent memory.
Recommendations Update to a version newer than 1.8.0.

Fix

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2025-15118
CLEANSTART-2026-AO61361
CVE-2025-12183
ECHO-CD33-EC70-D5F2
GHSA-VQF4-7M7X-WGFC
OPENSUSE-SU-2026:10317-1
RHSA-2026:1870
RHSA-2026:1871

Affected Products

Debian
Lz4-Java