CVE-2019-11922: Race Condition
Published Jul 25, 2019
·Updated
A race condition in the one-pass compression functions of Zstandard prior to version 1.3.8 could allow an attacker to write bytes out of bounds if an output buffer smaller than the recommended size was used.
Affected Software
2 affected componentsFixes available
Facebook Zstandard<1.3.8
debian/libzstd
1.4.8+dfsg-2.11.5.4+dfsg2-51.5.7+dfsg-11.5.7+dfsg-3
Remediation
Event History
Jul 25, 2019
CVE Published
via MITRE·08:32 PM
Data Sourced
via MITRE·08:32 PM
DescriptionWeakness
Jan 11, 2024
Data Sourced
via Launchpad·11:15 PM
Description
Feb 20, 2026
Data Sourced
via Ubuntu·10:32 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·10:33 PM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2019-11922?
CVE-2019-11922 is a vulnerability in the Zstandard compression library that could allow an attacker to write bytes out of bounds.
2
What is the severity of CVE-2019-11922?
CVE-2019-11922 has a severity rating of 8.1 (high).
3
How does CVE-2019-11922 affect Zstandard?
CVE-2019-11922 affects Zstandard versions prior to 1.3.8.
4
How can I fix CVE-2019-11922?
To fix CVE-2019-11922, it is recommended to update Zstandard to version 1.3.8 or later.
5
Where can I find more information about CVE-2019-11922?
You can find more information about CVE-2019-11922 on the MITRE CVE website, the GitHub repository for Zstandard, and the Facebook Security Advisories page.