Your message dated Sun, 30 Aug 2026 21:34:20 +0000
with message-id <[email protected]>
and subject line Bug#1122026: fixed in lz4-java 1.11.2+ds1-1
has caused the Debian Bug report #1122026,
regarding lz4-java: CVE-2025-12183 CVE-2025-66566
to be marked as done.

This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.

(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)


-- 
1122026: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1122026
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: lz4-java
Version: 1.8.0-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Control: found -1 1.8.0-4

Hi,

The following vulnerabilities were published for lz4-java.

CVE-2025-12183[0]:
| Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and
| earlier allow remote attackers to cause denial of service and read
| adjacent memory via untrusted compressed input.


CVE-2025-66566[1]:
| yawkat LZ4 Java provides LZ4 compression for Java. Insufficient
| clearing of the output buffer in Java-based decompressor
| implementations in lz4-java 1.10.0 and earlier allows remote
| attackers to read previous buffer contents via crafted compressed
| input. In applications where the output buffer is reused without
| being cleared, this may lead to disclosure of sensitive data. JNI-
| based implementations are not affected. This vulnerability is fixed
| in 1.10.1.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2025-12183
    https://www.cve.org/CVERecord?id=CVE-2025-12183
    https://www.openwall.com/lists/oss-security/2025/12/01/5
[1] https://security-tracker.debian.org/tracker/CVE-2025-66566
    https://www.cve.org/CVERecord?id=CVE-2025-66566
    https://github.com/yawkat/lz4-java/security/advisories/GHSA-cmp6-m4wj-q63q
    
https://github.com/yawkat/lz4-java/commit/33d180cb70c4d93c80fb0dc3ab3002f457e93840

Regards,
Salvatore

--- End Message ---
--- Begin Message ---
Source: lz4-java
Source-Version: 1.11.2+ds1-1
Done: tony mancill <[email protected]>

We believe that the bug you reported is fixed in the latest version of
lz4-java, which is due to be installed in the Debian FTP archive.

A summary of the changes between this version and the previous one is
attached.

Thank you for reporting the bug, which will now be closed.  If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.

Debian distribution maintenance software
pp.
tony mancill <[email protected]> (supplier of updated lz4-java package)

(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

Format: 1.8
Date: Sun, 30 Aug 2026 11:20:00 -0700
Source: lz4-java
Architecture: source
Version: 1.11.2+ds1-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers 
<[email protected]>
Changed-By: tony mancill <[email protected]>
Closes: 1122026 1145019
Changes:
 lz4-java (1.11.2+ds1-1) unstable; urgency=medium
 .
   * Migrate to github.com/yawkat/lz4-java/ for upstream
   * New upstream version 1.11.2
     - Addresses CVE-2025-66566, CVE-2025-12183 (Closes: #1122026)
     - Addresses CVE-2026-59949 (Closes: #1145019)
   * Freshen years in debian/copyright
   * Repack upstream tarball (+ds1) to exclude Maven wrapper JAR
   * liblz4-jni now links liblz4-java.so against liblz4.a instead of
     liblz4.so. Refer to debian/README.source for rationale.
   * Declare Static-Built-Using for liblz4-jni to detect when
     rebuilds/binNMUs are needed.
   * Refresh and drop unnecessary patches
   * Update build system to use maven-debian-helper
     - Add no-git-versioning-extension.patch
     - Add no-bnd-manifest.patch
     - Add exclude-fuzz-tests.patch
   * Enable Maven coordinate relocation for org.lz4:lz4-java
   * Enable tests during arch package build
   * Add debian/README.source
   * Add DEP-12 debian/upstream/metadata
   * Clean up unused Build-Depends
   * Remove liblz4-jni.lintian-overrides
   * Bump Standards-Version to 4.7.4
Checksums-Sha1:
 6c7a7e4c50f589ee0d2543cb462465a15206c06c 2336 lz4-java_1.11.2+ds1-1.dsc
 b246ca7e1c7b81a55c4fe9b92b608686e0169b43 443268 lz4-java_1.11.2+ds1.orig.tar.xz
 30104975b54008791d983fa094a75d936a3f6293 9660 
lz4-java_1.11.2+ds1-1.debian.tar.xz
 ad5ec9e2acee373d4b9274ed37410ff0a2448e00 15106 
lz4-java_1.11.2+ds1-1_arm64.buildinfo
Checksums-Sha256:
 9226982f038b158ad7e0f5409be4c115c300ffd1741c6e82e1e8ea7c868ea80e 2336 
lz4-java_1.11.2+ds1-1.dsc
 7f35bc1922cd77fd633d8917de666493c65e8eb349d5054809571b843872c726 443268 
lz4-java_1.11.2+ds1.orig.tar.xz
 f88092d9ca0f783adb0fd7245ec5256db5834dc50abeaba7404f583a56b60c0c 9660 
lz4-java_1.11.2+ds1-1.debian.tar.xz
 b4de4d155ff4dcbdeaec0548f0d1cc2869739cbe193f08c3c66304599d7224df 15106 
lz4-java_1.11.2+ds1-1_arm64.buildinfo
Files:
 f89e9d50ce997d48484acbc9582aafb4 2336 java optional lz4-java_1.11.2+ds1-1.dsc
 16572baa719430d8f7b7e5aea6f0db88 443268 java optional 
lz4-java_1.11.2+ds1.orig.tar.xz
 df3b709f10d36947e1323f7d11da7957 9660 java optional 
lz4-java_1.11.2+ds1-1.debian.tar.xz
 d88520de53339b128e32c29beedf1129 15106 java optional 
lz4-java_1.11.2+ds1-1_arm64.buildinfo

-----BEGIN PGP SIGNATURE-----

iQJIBAEBCgAyFiEE5Qr9Va3SequXFjqLIdIFiZdLPpYFAmqUncIUHHRtYW5jaWxs
QGRlYmlhbi5vcmcACgkQIdIFiZdLPpYzIA//Qcmtt7RpgTSpP7H9ZbhTPaINoFIY
281gD4nRuZbHb/2y5ahHjdAfTl0UKj0/1RXFAPOpEIejjFbUcZ2TAx1BY5vrcod3
J3+NNDzaB44ReM2/0An/MoOeAohOupaEPu9PNnAqYMbF0myL1Si2IftQ3yRIs7+W
EOVcAibEB2iX8YN7tMqX+5hs/FJqwEBuAJDiP6t09YEgQLC0OqYypKaUzCorq7od
lEjdhq/a6Y0S+YxKt2f+iUINhkTlQ+M95xHRsQKheKZy+PgvMPxADLKSce+nKsLw
AdWjhL/OOmozBJRH+ujsw4F0KCb+GUuCCKS+vrc4/a+gMiaVkbIYZwJ8edfdRC5n
tq00AOrw8Wxqc7rLaMMhgN0O89YWovufhrSDkIRlOxFqruOEwjt8SLP6EgC/O4I1
wLl+PPPWrebMK3nfhy42iqxwv9kMGUUyplDRTrmrWiHD2RmBjOAgRig8M+ZGudDO
hupkJKHonCGUeDrUxyDIOQxrC12Rz4UfYbFtxtWi9GtxFmhxQW2BW/FmL1v3x1Fj
ABx3X+X1B68OMgVqJmzj4HJ8HFGtUI7j9LB6Zzh/U82ZNM5YNemVSmsiR5TIgdr0
Xl01l1bnIiobNEepcntlrBjxsrfiPzdvkaAV95FNWjMJr0xOcTpoMFf5grKGqtGN
0YScadGFqhczgl0=
=p2ER
-----END PGP SIGNATURE-----

Attachment: pgpprO5Qfu8q8.pgp
Description: PGP signature


--- End Message ---

Reply via email to