Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-mcr4-qmvw-px4g | yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user |
Wed, 07 Oct 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 07 Oct 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-379 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Wed, 07 Oct 2026 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Yawkat
Yawkat lz4-java |
|
| Vendors & Products |
Yawkat
Yawkat lz4-java |
Tue, 06 Oct 2026 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4. | |
| Title | yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user | |
| Weaknesses | CWE-367 CWE-377 |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-10-07T18:26:06.020Z
Reserved: 2026-10-06T16:49:40.591Z
Link: CVE-2026-106451
Updated: 2026-10-07T18:25:55.855Z
Status : Awaiting Analysis
Published: 2026-10-06T20:17:27.173
Modified: 2026-10-07T19:17:32.463
Link: CVE-2026-106451
OpenCVE Enrichment
Updated: 2026-10-07T14:15:15Z
Github GHSA