Your submission was sent successfully! Close

CVE-2019-11922

Published: 25 July 2019

A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.

Priority

Medium

CVSS 3 base score: 8.1

Status

Package Release Status
libzstd
Launchpad, Ubuntu, Debian
bionic
Released (1.3.3+dfsg-2ubuntu1.1)
disco Not vulnerable
(1.3.8+dfsg-2)
eoan Not vulnerable
(1.3.8+dfsg-2)
focal Not vulnerable
(1.3.8+dfsg-2)
groovy Not vulnerable
(1.3.8+dfsg-2)
hirsute Not vulnerable
(1.3.8+dfsg-2)
impish Not vulnerable
(1.3.8+dfsg-2)
jammy Not vulnerable
(1.3.8+dfsg-2)
precise Does not exist

trusty Does not exist

upstream
Released (1.3.8+dfsg-2)
xenial Needed