{"id":"DEBIAN-CVE-2025-62813","details":"LZ4 through 1.10.0 allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact when the application processes untrusted LZ4 frames. For example, LZ4F_createCDict_advanced in lib/lz4frame.c mishandles NULL checks.","modified":"2025-10-31T04:32:30.274071Z","published":"2025-10-23T04:17:26Z","withdrawn":"2025-10-31T04:32:30.274071Z","upstream":["CVE-2025-62813"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2025-62813"}],"affected":[{"package":{"name":"lz4","ecosystem":"Debian:11","purl":"pkg:deb/debian/lz4?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.10.0-1","1.10.0-2","1.10.0-3","1.10.0-4","1.10.0-5","1.10.0-6","1.9.3-2","1.9.4-1","1.9.4-2","1.9.4-3","1.9.4-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62813.json"}},{"package":{"name":"lz4","ecosystem":"Debian:12","purl":"pkg:deb/debian/lz4?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.10.0-1","1.10.0-2","1.10.0-3","1.10.0-4","1.10.0-5","1.10.0-6","1.9.4-1","1.9.4-2","1.9.4-3","1.9.4-4"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62813.json"}},{"package":{"name":"lz4","ecosystem":"Debian:13","purl":"pkg:deb/debian/lz4?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.10.0-4","1.10.0-5","1.10.0-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62813.json"}},{"package":{"name":"lz4","ecosystem":"Debian:14","purl":"pkg:deb/debian/lz4?arch=source"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.10.0-4","1.10.0-5","1.10.0-6"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2025-62813.json"}}],"schema_version":"1.7.3"}