AETERNAE AI RESEARCH LLC INDEPENDENT RESEARCH
ÆAETERNAERESEARCH
Sign inRequest access
← CVE index
Δ / VULNERABILITY RECORD

CVE-2026-106451.

Source-reported disclosure and enrichment record.

SEVERITY / CVSSHIGH / 7.3CVSS 4.0 · GitHub reviewed advisory
EXPLOITATION STATUSNot listed in the cached KEV catalogThis does not establish absence of exploitation.
RECORD STATUSGitHub reviewed advisoryModified Oct 07, 2026

Disclosure summary

### Summary When no system-installed `liblz4-java` is found, `net.jpountz.util.Native.load()` extracts the bundled native library to `java.io.tmpdir` and loads it with `System.load`. The path of the extracted library can be predicted before it is created, and the library file is opened without exclusive creation. Another local user who can write to the same temporary directory can therefore create the file first and control the code that is loaded. ### Details ```java tempLibLock = File.createTempFile("liblz4-java-", "." + os().libExtension + ".lck"); tempLib = new File(tempLibLock.getAbsolutePath().replaceFirst(".lck$", "")); // copy to tempLib try (FileOutputStream out = new FileOutputStream(tempLib)) { ... } ... System.load(tempLib.getAbsolutePath()); ``` Only the `.lck` file is created safely, with a random name and exclusive creation. The library path is the `.lck` name without the `.lck` suffix, and nothing reserves it. `new FileOutputStream(tempLib)` opens it with `O_CREAT|O_TRUNC` and follows symlinks. In a shared, world-writable temporary directory, another user can watch for the `.lck` file and create the corresponding library file before it is opened. If they win that ra

Source-specific records & product guidance

Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.

GitHub Reviewed Security Advisories · GHSA-mcr4-qmvw-px4g

Open original source · Updated Oct 07, 2026

yawkat LZ4 Java: Native library extraction to a shared temporary directory is vulnerable to file replacement by another local user

Source severity: HIGH / 7.3

EcosystemPackageAffected rangeFirst patched
mavenat.yawk.lz4:lz4-java1.11.4
mavenorg.lz4:lz4-java>= 1.7.0,Not supplied

Original records & references

PUBLISHED 2026-10-07T16:35:51-04:00
MODIFIED 2026-10-07T16:35:52-04:00
INGESTED 2026-10-08T12:30:39-04:00