๐Ÿ” CVE Alert

CVE-2026-106451

UNKNOWN 0.0

yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4.

CWE CWE-367 CWE-377
Vendor yawkat
Product lz4-java
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for yawkat lz4-java

Be the first to know when new unknown vulnerabilities affecting yawkat lz4-java are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

yawkat / lz4-java
< 1.11.4

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/yawkat/lz4-java/security/advisories/GHSA-mcr4-qmvw-px4g github.com: https://github.com/yawkat/lz4-java/commit/7a48b7f6b8099b9dab6541e4ac2ee0979dc55aa3 github.com: https://github.com/yawkat/lz4-java/releases/tag/v1.11.4