The vendor explicitly identifies these products as affected by this CVE.
- exploit-intelligence/agent-client-rhel9 as a component of Exploit Intelligence
- jenkins-2-plugins.src as a component of OpenShift Developer Tools and Services
- ocp-tools-4/jenkins-rhel8 as a component of OpenShift Developer Tools and Services
- ocp-tools-4/jenkins-rhel9 as a component of OpenShift Developer Tools and Services
- zstd-jni as a component of Red Hat build of Apache Camel 4 for Quarkus 3
- zstd-jni as a component of Red Hat build of Apache Camel for Spring Boot 4
- zstd-jni as a component of Red Hat build of Apicurio Registry 3
- zstd-jni as a component of Red Hat build of Debezium 3
- zstd-jni as a component of Red Hat build of Quarkus
- libarrow as a component of Red Hat Ceph Storage 9
- libarrow-doc as a component of Red Hat Ceph Storage 9
- libarrow.src as a component of Red Hat Ceph Storage 9
- Summary
- A flaw was found in zstd-jni. This vulnerability occurs due to insufficient validation of offset and length parameters within the `ZstdDictCompress` constructor. An attacker can exploit this by providing untrusted values, leading to an out-of-bounds memory read. This can result in the disclosure of sensitive native heap memory and cause the Java Virtual Machine (JVM) to crash, leading to a denial of service.
- Remediation
- Update com.github.luben/zstd-jni to version 1.5.7-14 or later. Until updated, do not pass attacker-controlled offset or length values to ZstdDictCompress.
