CVE-2024-36124 Information

Description

iq80 Snappy is a compression/decompression library. When uncompressing certain data Snappy tries to read outside the bounds of the given byte arrays. Because Snappy uses the JDK class sun.misc.Unsafe to speed up memory access no additional bounds checks are performed and this has similar security consequences as out-of-bounds access in C or C++ namely it can lead to non-deterministic behavior or crash the JVM. iq80 Snappy is not actively maintained anymore. As quick fix users can upgrade to version 0.5.

Reference

https://github.com/dain/snappy/security/advisories/GHSA-8wh2-6qhj-h7j9

Share on: