PatchSiren

PSeitz CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH PSeitz CVE published 2026-03-20

CVE-2026-32829

The lz4_flex library, a pure Rust implementation of LZ4 compression/decompression, has a vulnerability in versions 0.11.5 and below, and 0.12.0. This vulnerability allows decompressing invalid LZ4 data to leak sensitive information from uninitialized memory or previous decompression operations due to improper validation of offset values during LZ4 'match copy operations.' The block-based API functions are [truncated]