CVE-2019-11922

HIGH

Zstandard <1.3.8 - Memory Corruption

Title source: llm
STIX 2.1

Description

A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.

References (7)

Core 7
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
https://usn.ubuntu.com/4108-1/

Scores

CVSS v3 8.1
EPSS 0.0142
EPSS Percentile 69.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-362
Status published
Products (1)
facebook/zstandard < 1.3.8
Published Jul 25, 2019
Tracked Since Feb 18, 2026