CVE-2018-16985: Lizard Project Lizard

High severity, CVSS 7.5. EPSS: 1.5% chance of exploitation in the next 30 days.

In Lizard (formerly LZ5) 2.0, use of an invalid memory address was discovered in LZ5_compress_continue in lz5_compress.c, related to LZ5_compress_fastSmall and MEM_read32. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

Affected products

Published 2018-09-13. Last modified 2026-06-17.