Skip to content

Update lz4 to 1.10.0 for CVE-2014-4715, CVE-2021-3520, CVE-2019-17543#19

Merged
rfuest merged 1 commit into
gtkwave:mainfrom
maliberty:lz4-1.10.0-cve
Jun 18, 2026
Merged

Update lz4 to 1.10.0 for CVE-2014-4715, CVE-2021-3520, CVE-2019-17543#19
rfuest merged 1 commit into
gtkwave:mainfrom
maliberty:lz4-1.10.0-cve

Conversation

@maliberty

Copy link
Copy Markdown
Contributor

No description provided.

@rfuest

rfuest commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Where did you get the updated version from? The files don't match the 1.10.0 release on the lz4 GitHub page.

@maliberty

Copy link
Copy Markdown
Contributor Author

I got the head commit 0774d05537f9762f838f7ab541b7765f1a729cb5 not the release tag. I can take the specific 1.10.0 if you prefer.

@rfuest

rfuest commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

I got the head commit 0774d05537f9762f838f7ab541b7765f1a729cb5 not the release tag. I can take the specific 1.10.0 if you prefer.

Yes, I prefer to stick with the latest stable release, especially for a security related update. I don't know how stable development versions of LZ4 are and the 1.10.0 release has been out for 2 years without any further CVEs.

Signed-off-by: Matt Liberty <mliberty@precisioninno.com>
@maliberty

Copy link
Copy Markdown
Contributor Author

done

@rfuest rfuest merged commit cf74bef into gtkwave:main Jun 18, 2026
3 checks passed
@rfuest

rfuest commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

Thanks.

@tbybell

tbybell commented Jun 18, 2026

Copy link
Copy Markdown
Contributor

lz4.c/lz4.h updated in LTS, thanks.

3c922be..6dcb09c lts -> lts

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants