CVE-2026-106451: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition in yawkat lz4-java
Description
A time-of-check to time-of-use (TOCTOU) race condition exists in yawkat lz4-java versions prior to 1.11.4. The vulnerability arises from the way temporary files are created and used during native library loading, allowing a local attacker with access to the shared temporary directory to replace the library file before it is loaded. This can lead to execution of arbitrary native code. Systems with hardened protections or alternative configurations may fail to load the malicious library and fall back to Java implementations. The issue is fixed in version 1.11.4.
CVSS v4.0
Score 7.3high
Affected software
yawkat
lz4-java
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
yawkat lz4-java versions from 1.7.0 up to but not including 1.11.4 contain a TOCTOU race condition in the native library loading process. The method net.jpountz.util.Native.load() creates a temporary .lck file exclusively but then derives the native library path by removing the suffix. The subsequent FileOutputStream opens this predictable path without exclusive creation, enabling a local user with access to the shared temporary directory to create or replace the native library file before System.load() uses it. Exploitation depends on shared-directory permissions, host protections, and winning the race condition. Successful exploitation can lead to arbitrary native code execution in the victim process. Systems using a system library, a private java.io.tmpdir, or Java-only implementations are not affected. The vulnerability is resolved in version 1.11.4.
Potential Impact
An attacker with local access to the shared temporary directory can exploit this race condition to execute arbitrary native code within the context of the victim process using the vulnerable yawkat lz4-java library. This can lead to privilege escalation or other malicious actions depending on the victim's privileges. Hardened systems may prevent exploitation by causing library loading to fail and falling back to Java implementations, reducing impact.
Mitigation Recommendations
Upgrade to yawkat lz4-java version 1.11.4 or later, where this vulnerability is fixed. Alternatively, use configurations that avoid the vulnerable code path, such as using a system library, a private java.io.tmpdir, or Java-only implementations. No other specific mitigations are indicated.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-10-06T16:49:40.591Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6ac5544a2cdf04f656d9e12f
Added to database: 10/06/2026, 20:04:26 UTC
Last enriched: 10/06/2026, 20:18:12 UTC
Last updated: 10/06/2026, 20:19:15 UTC
Views: 3
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.