Repository navigation
[fix][sec] Upgrade lz4-java to 1.11.1 to address CVE-2026-59949 - #26250
Merged
Merged
Conversation
Insufficient validation of byte array arguments in the JNI-based XXHash implementations in lz4-java <= 1.11.0 allows a caller to crash the JVM by passing a null array reference or an out-of-range off/len to the native XXHash methods (GHSA-xx22-p4ch-683r, CVSS 6.5 medium). lz4-java ships in the server distribution transitively via BookKeeper's distributedlog-common, so upgrade it to the fixed 1.11.1 release. Assisted-by: Claude Code (Opus 5)
nodece
approved these changes
Jul 27, 2026
lhotari
added a commit
that referenced
this pull request
Aug 4, 2026
(cherry picked from commit bbd1970)
lhotari
added a commit
that referenced
this pull request
Aug 4, 2026
(cherry picked from commit bbd1970)
nodece
pushed a commit
to ascentstream/pulsar
that referenced
this pull request
Aug 28, 2026
…he#26250) (cherry picked from commit bbd1970) Signed-off-by: Zixuan Liu <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Motivation
CVE-2026-59949 (medium, CVSS 6.5,
CWE-125 / CWE-476) affects
at.yawk.lz4:lz4-java<= 1.11.0.Insufficient validation of byte array arguments in the JNI-based XXHash implementations lets a
caller crash the JVM by passing an invalid array reference or an invalid range to the native
XXHash methods:
SafeUtils.checkRange(byte[], int, int)skipped all array access whenlen == 0, sohash(null, 0, 0, seed)could pass a null array to JNI and fault inGetPrimitiveArrayCritical.bytes/off/lenat all, soupdate(new byte[16], 0, Integer.MAX_VALUE)could read far past the end of the Java arraybefore crashing.
The pure-Java (
safeInstance()) XXHash implementations are not affected, and the LZ4compression APIs are not the subject of the advisory.
Exposure in Pulsar is limited but the vulnerable jar does ship. Pulsar's own LZ4 codec
(
CompressionCodecLZ4) uses aircompressor, not lz4-java, and no Pulsar source calls the XXHashAPIs at all. However,
at.yawk.lz4:lz4-javareaches the server distribution transitively viaBookKeeper's
distributedlog-common, solib/at.yawk.lz4-lz4-java-1.11.0.jaris bundled in therelease tarball and is reported by dependency scanners.
Modifications
Upgrade
at.yawk.lz4:lz4-javafrom 1.11.0 to the fixed 1.11.1 release:gradle/libs.versions.toml—lz4java = "1.11.1". The version catalog drives the enforcedplatform (
pulsar-dependencies), so this also pins the transitive BookKeeper/distributedlogresolution.
distribution/server/src/assemble/LICENSE.bin.txt— update the bundled jar name.Upstream 1.11.1 is a security-only patch release
(v1.11.0...v1.11.1 — two commits,
one of which is a docs-only change). The fix adds argument validation only: no public API change,
no signature change, no new transitive dependencies, unchanged Java 7 target, and the bundled
native libraries are byte-identical to 1.11.0, so compression output cannot change.
Verifying this change
This change is a dependency upgrade without new test coverage; it is covered by existing tests.
Verified locally:
./gradlew checkBinaryLicensepasses for both the server and shell distributions. This check isbidirectional (every bundled jar must be listed in
LICENSE.bin.txtand vice versa), so itconfirms the new version both resolves and is correctly recorded.
lib/at.yawk.lz4-lz4-java-1.11.1.jar../gradlew :pulsar-common:test --tests CompressorCodecBackwardCompatTest --tests CompressorCodecTestpasses — 51 tests, 0 failures, 0 skipped.
CompressorCodecBackwardCompatTestexercises theupgraded library directly via
CompressionCodecLZ4JNI, checking LZ4 JNI ↔ aircompressorround-trips in both directions, which guards the on-the-wire compression format.
./gradlew spotlessCheck checkstyleMain checkstyleTestpasses.Does this pull request potentially affect one of the following parts: