CVE-2026-32829

EUVD-2026-13426
lz4_flex is a pure Rust implementation of LZ4 compression/decompression. In versions 0.11.5 and below, and 0.12.0,  decompressing invalid LZ4 data can leak sensitive information from uninitialized memory or from previous decompression operations. The library fails to properly validate offset values during LZ4 "match copy operations," allowing out-of-bounds reads from the output buffer. The block-based API functions (`decompress_into`, `decompress_into_with_dict`, and others when `safe-decode` is disabled) are affected, while all frame APIs are unaffected. The impact is potential exposure of sensitive data and secrets through crafted or malformed LZ4 input. This issue has been fixed in versions 0.11.6 and 0.12.1.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 35%
Affected Products (NVD)
VendorProductVersion
pseitzlz4_flex
𝑥
< 0.11.6
pseitzlz4_flex
0.12.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
rust-lz4-flex
forky
0.13.0-1
fixed
sid
0.13.0-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
rust-lz4-flex
jammy
dne
noble
needs-triage
questing
needs-triage
resolute
needs-triage
Amazon Linux logo
Amazon Linux Releases
Amazon Package
Release
cargo
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed
clippy
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed
rust
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed
rust-analyzer
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed
rust-debugger-common
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed
rust-doc
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed
rust-gdb
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed
rust-src
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed
rust-std-static
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed
rust-toolset
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed
rust-toolset-srpm-macros
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed
rustfmt
Amazon Linux 2
0:1.93.0-1.amzn2.0.1
fixed