Double Release Vulnerability in Xerial Snappy-Java Library
CVE-2026-108104
6.3MEDIUM
What is CVE-2026-108104?
The vulnerability in Xerial's snappy-java library arises from a flaw in the SnappyFramedInputStream component, where improper handling of pooled buffers can result in a double release condition. This can occur when an attacker crafts framed data with an excessively large declared chunk length, leading to an OutOfMemoryError. As a consequence, shared backing arrays may inadvertently expose or overwrite decompressed data from other streams, presenting significant data security risks.
Affected Version(s)
snappy-java 1.1.7.4 < 1.1.10.10
snappy-java 1.1.10.10
