CVE-2025-12183
ADVISORY - githubSummary
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
This is fixed in a forked release: at.yawk.lz4:lz4-java version 1.8.1. The original project has been archived: https://github.com/lz4/lz4-java, and Sonatype has added a redirect from org.lz4:lz4-java:1.8.1 to the new group ID.
Common Weakness Enumeration (CWE)
Out-of-bounds Read
Out-of-bounds Read
Out-of-bounds Read
NIST
-
CVSS SCORE
8.8highGitHub
-
CVSS SCORE
8.8highDebian
-
Ubuntu
-
CVSS SCORE
N/AmediumRed Hat
2.2
CVSS SCORE
6.5mediumChainguard
CGA-ffgj-j23r-xf6f
-
minimos
MINI-225v-h7g5-q6gp
-
minimos
MINI-24v6-26wh-p8v4
-
minimos
MINI-2vhh-cm6r-xcgj
-
minimos
MINI-48r7-m853-wqcm
-
minimos
MINI-495g-8688-hxjp
-
minimos
MINI-4xf2-3qcj-jc8w
-
minimos
MINI-5fjx-pf4c-2qq7
-
minimos
MINI-5hwv-h9jj-rcf5
-
minimos
MINI-687c-hhpv-3453
-
minimos
MINI-73m6-w6qw-h8xc
-
minimos
MINI-7h6f-h5f7-qmgh
-
minimos
MINI-7x8q-mm54-xrg8
-
minimos
MINI-8jxp-f63f-4r35
-
minimos
MINI-9jp7-7pcc-rqhf
-
minimos
MINI-c35j-3rq6-7jhc
-
minimos
MINI-c7rf-5hpw-2whv
-
minimos
MINI-cm7m-wq72-h427
-
minimos
MINI-cw8p-9p3q-mxqw
-
minimos
MINI-f8c3-r5h9-w89j
-
minimos
MINI-fmqj-v36r-6crq
-
minimos
MINI-g3c3-28rq-57gp
-
minimos
MINI-gq7r-322c-4xh9
-
minimos
MINI-h53g-8fq2-mvqv
-
minimos
MINI-hv8f-h7xm-h32q
-
minimos
MINI-j82v-c5j3-2c5m
-
minimos
MINI-m4jf-8wg4-w623
-
minimos
MINI-mcq6-f95g-h57v
-
minimos
MINI-mgj6-3pjx-h6r8
-
minimos
MINI-mhqg-g944-6rvf
-
minimos
MINI-p4c4-4h4q-653p
-
minimos
MINI-pm2w-p68h-q4jm
-
minimos
MINI-pq6h-v3j7-w42h
-
minimos
MINI-pr2x-h6f3-hx7x
-
minimos
MINI-pvcx-8qfx-xqfm
-
minimos
MINI-qvcm-92f4-xg54
-
minimos
MINI-r39q-xp5h-3r37
-
minimos
MINI-r4q4-rq73-mcq4
-
minimos
MINI-v487-p4xx-j3gf
-
minimos
MINI-vf6x-9qjg-mrw6
-
minimos
MINI-vmxq-c9rp-p22f
-
minimos
MINI-w42f-3w2r-838h
-
minimos
MINI-w7j6-7cjf-f7cw
-
minimos
MINI-wqww-6jgv-v8ch
-
minimos
MINI-wr5w-ph98-323m
-