CVE-2026-106451

LOWCVSS 7.3 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

yawkat LZ4 Java provides LZ4 compression for Java. From 1.7.0 until 1.11.4, net.jpountz.util.Native.load() uses File.createTempFile to create an exclusive temporary .lck file but derives the native-library path by removing the suffix, then FileOutputStream opens that predictable path without exclusive creation, allowing another local user with access to the same shared temporary directory to create or replace the library file before System.load() uses it. Successful exploitation depends on shared-directory permissions, host protections, and winning the race, and can execute native code as the victim; hardened systems may instead cause library loading to fail and fall back to Java implementations. Configurations using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. This issue is fixed in version 1.11.4.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367CWE-377

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-10-08: 110-08
Referenced assets1 URL
Full discourse1 post
  • DailyCVE@dailycve

    🔴 (lz4-#java), Time-of-check Time-of-use (TOCTOU) Race Condition, #CVE-2026-106451 (High) -DC-Oct2026-2857 https://dailycve.com/lz4-java-time-of-check-time-of-use-toctou-race-condition-cve-2026-106451-high-dc-oct2026-2857/

    0000026
    239 followersView on X

Explore more