SCA: security update for io.airlift:aircompressor, io.airlift:aircompressor-v3 (GHSA-vx9q-rhv9-3jvg)

medium Tenable Self-Hosted Container Security Plugin ID 436376

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Aircompressor is a library with ports of the Snappy, LZO, LZ4, and Zstandard compression algorithms to
Java. In versions 3.3 and below, incorrect handling of malformed data in Java-based decompressor
implementations for Snappy and LZ4 allow remote attackers to read previous buffer contents via crafted
compressed input. With certain crafted compressed inputs, elements from the output buffer can end up in
the uncompressed output, potentially leaking sensitive data. This is relevant for applications that reuse
the same output buffer to uncompress multiple inputs. This can be the case of a web server that allocates
a fix-sized buffer for performance purposes. There is similar vulnerability in GHSA-cmp6-m4wj-q63q. This
issue is fixed in version 3.4. (CVE-2025-67721)

See Also

https://github.com/advisories/GHSA-vx9q-rhv9-3jvg

Plugin Details

Severity: Medium

ID: 436376

Version: Revision 1.12

Type: Local

Family: SCA Checks

Published: 12/13/2025

Updated: 6/30/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 3

Percentile: 23.73

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: High

Base Score: 7.8

Temporal Score: 5.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:N/A:N

CVSS Score Source: CVE-2025-67721

CVSS v3

Risk Factor: High

Base Score: 7.5

Temporal Score: 6.5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

CVSS v4

Risk Factor: Medium

Base Score: 6.3

Threat Score: 1.7

Threat Vector: CVSS:4.0/E:U

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/12/2025

Vulnerability Publication Date: 12/12/2025

Reference Information

CVE: CVE-2025-67721