zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.
History

Thu, 10 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Luben
Luben zstd-jni
Vendors & Products Luben
Luben zstd-jni

Thu, 10 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description zstd-jni versions before 1.5.7-14 fail to validate closed state in setDict, setLongMax, setLevel and setRefMultipleDDicts methods of stream classes. Attackers can call these methods on closed streams to write through freed native pointers, corrupting unrelated objects or crashing the JVM.
Title zstd-jni 1.3.8-4 through 1.5.7-13 Use-After-Free via Setters Called After close()
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}

cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-09-09T14:32:45.512Z

Updated: 2026-09-09T15:57:53.652Z

Reserved: 2026-09-09T14:02:07.708Z

Link: CVE-2026-87877

cve-icon Vulnrichment

Updated: 2026-09-09T15:57:47.831Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-09T15:17:28.070

Modified: 2026-09-09T20:16:54.383

Link: CVE-2026-87877

cve-icon Redhat

Severity : Important

Publid Date: 2026-09-09T14:32:45Z

Links: CVE-2026-87877 - Bugzilla