CVE-2025-12183: org.lz4:lz4-java - Out-of-Bounds Memory Access
Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier allow remote attackers to cause denial of service and read adjacent memory via untrusted compressed input.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
maven/org.lz4:lz4-javato a version that resolves this vulnerability.Fixed in 1.8.1 - Upgrade
Upgrade
maven/at.yawk.lz4:lz4-javato a version that resolves this vulnerability.Fixed in 1.8.1 - Upgrade
Upgrade
at.yawk.lz4:lz4-javato a version that resolves this vulnerability.Fixed in 1.8.1
Event History
Frequently Asked Questions
What is the severity of CVE-2025-12183?
CVE-2025-12183 has been classified with a high severity due to its potential to cause denial of service and memory read vulnerabilities.
How do I fix CVE-2025-12183?
To mitigate CVE-2025-12183, upgrade to lz4-java version 1.8.1 or later.
What causes CVE-2025-12183?
CVE-2025-12183 is caused by out-of-bounds memory operations in lz4-java 1.8.0 and earlier when handling untrusted compressed input.
What potential impacts does CVE-2025-12183 have?
The impacts of CVE-2025-12183 include remote denial of service and possible exposure of adjacent memory.
Is CVE-2025-12183 exploitable remotely?
Yes, CVE-2025-12183 can be exploited remotely through untrusted input sent to the vulnerable lz4-java implementation.