Skip to content

[fix][sec] Upgrade lz4-java to 1.11.1 to address CVE-2026-59949 - #26250

Merged
nodece merged 1 commit into
apache:masterfrom
lhotari:lh-fix-lz4java-cve-2026-59949
Jul 27, 2026
Merged

nodece merged 1 commit into
apache:masterfrom
lhotari:lh-fix-lz4java-cve-2026-59949

Conversation

@lhotari

@lhotari lhotari commented Jul 27, 2026

Copy link
Copy Markdown
Member

Motivation

CVE-2026-59949 (medium, CVSS 6.5,
CWE-125 / CWE-476) affects at.yawk.lz4:lz4-java <= 1.11.0.

Insufficient validation of byte array arguments in the JNI-based XXHash implementations lets a
caller crash the JVM by passing an invalid array reference or an invalid range to the native
XXHash methods:

  • SafeUtils.checkRange(byte[], int, int) skipped all array access when len == 0, so
    hash(null, 0, 0, seed) could pass a null array to JNI and fault in
    GetPrimitiveArrayCritical.
  • The streaming JNI implementations did not validate bytes/off/len at all, so
    update(new byte[16], 0, Integer.MAX_VALUE) could read far past the end of the Java array
    before crashing.

The pure-Java (safeInstance()) XXHash implementations are not affected, and the LZ4
compression APIs are not the subject of the advisory.

Exposure in Pulsar is limited but the vulnerable jar does ship. Pulsar's own LZ4 codec
(CompressionCodecLZ4) uses aircompressor, not lz4-java, and no Pulsar source calls the XXHash
APIs at all. However, at.yawk.lz4:lz4-java reaches the server distribution transitively via
BookKeeper's distributedlog-common, so lib/at.yawk.lz4-lz4-java-1.11.0.jar is bundled in the
release tarball and is reported by dependency scanners.

Modifications

Upgrade at.yawk.lz4:lz4-java from 1.11.0 to the fixed 1.11.1 release:

  • gradle/libs.versions.toml — lz4java = "1.11.1". The version catalog drives the enforced
    platform (pulsar-dependencies), so this also pins the transitive BookKeeper/distributedlog
    resolution.
  • distribution/server/src/assemble/LICENSE.bin.txt — update the bundled jar name.

Upstream 1.11.1 is a security-only patch release
(v1.11.0...v1.11.1 — two commits,
one of which is a docs-only change). The fix adds argument validation only: no public API change,
no signature change, no new transitive dependencies, unchanged Java 7 target, and the bundled
native libraries are byte-identical to 1.11.0, so compression output cannot change.

Verifying this change

  • Make sure that the change passes the CI checks.

This change is a dependency upgrade without new test coverage; it is covered by existing tests.

Verified locally:

  • ./gradlew checkBinaryLicense passes for both the server and shell distributions. This check is
    bidirectional (every bundled jar must be listed in LICENSE.bin.txt and vice versa), so it
    confirms the new version both resolves and is correctly recorded.
  • The assembled server tarball contains lib/at.yawk.lz4-lz4-java-1.11.1.jar.
  • ./gradlew :pulsar-common:test --tests CompressorCodecBackwardCompatTest --tests CompressorCodecTest
    passes — 51 tests, 0 failures, 0 skipped. CompressorCodecBackwardCompatTest exercises the
    upgraded library directly via CompressionCodecLZ4JNI, checking LZ4 JNI ↔ aircompressor
    round-trips in both directions, which guards the on-the-wire compression format.
  • ./gradlew spotlessCheck checkstyleMain checkstyleTest passes.

Does this pull request potentially affect one of the following parts:

  • Dependencies (add or upgrade a dependency)
  • The public API
  • The schema
  • The default values of configurations
  • The threading model
  • The binary protocol
  • The REST endpoints
  • The admin CLI options
  • The metrics
  • Anything that affects deployment

Insufficient validation of byte array arguments in the JNI-based XXHash
implementations in lz4-java <= 1.11.0 allows a caller to crash the JVM by
passing a null array reference or an out-of-range off/len to the native
XXHash methods (GHSA-xx22-p4ch-683r, CVSS 6.5 medium).

lz4-java ships in the server distribution transitively via BookKeeper's
distributedlog-common, so upgrade it to the fixed 1.11.1 release.

Assisted-by: Claude Code (Opus 5)
@nodece
nodece merged commit bbd1970 into apache:master Jul 27, 2026
43 checks passed
lhotari added a commit that referenced this pull request Aug 4, 2026
lhotari added a commit that referenced this pull request Aug 4, 2026
nodece pushed a commit to ascentstream/pulsar that referenced this pull request Aug 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants