SCA: security update for at.yawk.lz4:lz4-java, org.lz4:lz4-java (GHSA-mcr4-qmvw-px4g)

high Tenable Cloud Security Plugin ID 473791

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load()
uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by
removing the suffix, then FileOutputStream opens that predictable path without exclusive creation,
allowing another local user with access to the same shared temporary directory to create or replace the
library file before System.load() uses it. Successful exploitation depends on shared-directory
permissions, host protections, and winning the race, and can execute native code as the victim; hardened
systems may instead cause library loading to fail and fall back to Java implementations. Configurations
using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This
issue is fixed in version 1.11.4. (CVE-2026-106451)

Solution

Update the at.yawk.lz4:lz4-java library and its related packages to version 1.11.4 or later.

See Also

https://github.com/advisories/GHSA-mcr4-qmvw-px4g

Plugin Details

Severity: High

ID: 473791

Version: Revision 1.1

Type: Local

Family: SCA Checks

Published: 10/8/2026

Updated: 10/8/2026

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.38

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Low

Base Score: 3.3

Temporal Score: 2.4

Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:N

CVSS Score Source: CVE-2026-106451

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 6.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: High

Base Score: 7.3

Threat Score: 4.4

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 10/7/2026

Vulnerability Publication Date: 10/6/2026

Reference Information

CVE: CVE-2026-106451