Description
There are packages installed that are affected by a vulnerability referenced in the following CVE:
- yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load()
uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by
removing the suffix, then FileOutputStream opens that predictable path without exclusive creation,
allowing another local user with access to the same shared temporary directory to create or replace the
library file before System.load() uses it. Successful exploitation depends on shared-directory
permissions, host protections, and winning the race, and can execute native code as the victim; hardened
systems may instead cause library loading to fail and fall back to Java implementations. Configurations
using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This
issue is fixed in version 1.11.4. (CVE-2026-106451)
Solution
Update the hono-service-device-registry-jdbc library and its related packages to version 2.7.0-r46 or later.
Plugin Details
Risk Information
Vector: CVSS2#AV:L/AC:M/Au:N/C:P/I:P/A:N
Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
Threat Vector: CVSS:4.0/E:U
Vector: CVSS:4.0/AV:L/AC:H/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Vulnerability Information
Exploit Ease: No known exploits are available
Vulnerability Publication Date: 10/6/2026