CVE-2026-87795

high Red Hat
CVSS v3 Base Score
8.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
Low
Integrity
None
Availability
High
Published: September 9, 2026 (1 days ago)
Last Modified: September 9, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in zstd-jni. This vulnerability occurs due to insufficient validation of offset and length parameters within the `ZstdDictCompress` constructor. An attacker can exploit this by providing untrusted values, leading to an out-of-bounds memory read. This can result in the disclosure of sensitive native heap memory and cause the Java Virtual Machine (JVM) to crash, leading to a denial of service.

Affected Products

Exploit IntelligenceOpenShift Developer Tools and ServicesRed Hat build of Apache Camel 4 for Quarkus 3Red Hat build of Apache Camel for Spring Boot 4Red Hat build of Apicurio Registry 3Red Hat build of Debezium 3Red Hat build of QuarkusRed Hat Ceph Storage 9Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References