Skip to content

[GHSA-pm27-vjq7-f5fv] snappy-java through 1.1.10.8 contains a buffer overflow... - #9855

Open
portyu9 wants to merge 1 commit into
portyu9/advisory-improvement-9855from
portyu9-GHSA-pm27-vjq7-f5fv
Open

portyu9 wants to merge 1 commit into
portyu9/advisory-improvement-9855from
portyu9-GHSA-pm27-vjq7-f5fv

Conversation

@portyu9

@portyu9 portyu9 commented Sep 29, 2026 •

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CVSS v4
  • Source code location
  • Summary

Comments
Add the missing Maven package mapping and affected-version information for CVE-2026-93452 / GHSA-pm27-vjq7-f5fv.

The affected Maven artifact is org.xerial.snappy:snappy-java.

Version 1.1.10.8 contains the vulnerable Snappy.compress(ByteBuffer, ByteBuffer) implementation. The method validates that both buffers are direct, but does not validate that the destination buffer has enough remaining capacity before calling the native rawCompress implementation.

The current upstream remediation is PR 733 below, which adds a maxCompressedLength() capacity check before the native compression call. That PR remains open and unmerged, and no patched release is currently available.

Affected package: org.xerial.snappy:snappy-java
Affected versions: <= 1.1.10.8
Patched version: none currently available

Vulnerable source:
https://github.com/xerial/snappy-java/blob/v1.1.10.8/src/main/java/org/xerial/snappy/Snappy.java#L137-L161

Proposed upstream fix:
xerial/snappy-java#733

@github-actions
github-actions Bot changed the base branch from main to portyu9/advisory-improvement-9855 September 29, 2026 16:13
@portyu9

portyu9 commented Sep 29, 2026

Copy link
Copy Markdown
Author

Correction: the form submission unintentionally removed the existing CVSS v3 vector. The intended change is to keep CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H unchanged while adding the Maven package mapping, affected-version range, summary, source location, and form-safe CVSS v4 vector.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant