← Back

CVE-2019-11922

nvd nist
Published: Jul 25, 2019Modified: Jun 17, 2026

JSON object

Loading...
8.1
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: NVD

Description

A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.

Affected (1)

Products: Facebook: Zstandard
1 product
Zstandard
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 1.3.8

Timeline

No history available yet.