CVE-2026-32829

🟡 Monitoruj

Nieprawidłowe odczyty w lz4_flex mogą prowadzić do ujawnienia wrażliwych danych z niezainicjowanej pamięci podczas dekompresji.

CVSS
7.5
EPSS
0.6%
Exploit
none
Vendor
pseitz
Opis źródłowy (NVD)

lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0, decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from previous decompression operations. The library fails to properly validate offset values during LZ4 "match copy operations," allowing out-of-bounds reads from the output buffer. The block-based API functions (`decompress_into`, `decompress_into_with_dict`, and others when `safe-decode` is disabled) are affected, while all frame APIs are unaffected. The impact is potential exposure of sensitive data and secrets through crafted or malformed LZ4 input. This issue has been fixed in versions 0.11.6 and 0.12.1.

brak Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS7.5
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.6%
Opublikowano (NVD)2026-03-20 01:15:56 UTC
Ostatnia modyfikacja (NVD)2026-09-17 12:17:49 UTC
Referencje