VulnerabilityModified
CVE-2019-11922
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
HIGH 8.1EPSS 1.42%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.42%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
- CVSS 3.0
- 8.1 HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.42% probability · 71th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-362
- Affected
- facebook/zstandard
- Source
- cve-assign@fb.com
References
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00062.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00078.html
- https://github.com/facebook/zstd/pull/1404/commits/3e5cdf1b6a85843e991d7d10f6a2567c15580da0Patch, Third Party Advisory
- https://usn.ubuntu.com/4108-1/
- https://www.facebook.com/security/advisories/cve-2019-11922Vendor Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00008.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00062.html
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00078.html
- https://github.com/facebook/zstd/pull/1404/commits/3e5cdf1b6a85843e991d7d10f6a2567c15580da0Patch, Third Party Advisory
- https://usn.ubuntu.com/4108-1/
- https://www.facebook.com/security/advisories/cve-2019-11922Vendor Advisory
- https://www.oracle.com/security-alerts/cpuoct2020.html
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.