CVE-2022-4899

A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
Affected Products (NVD)
VendorProductVersion
facebookzstandard
1.4.10
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
libzstd
bookworm
1.5.4+dfsg2-5
fixed
bullseye
no-dsa
buster
not-affected
sid
1.5.6+dfsg-1
fixed
trixie
1.5.6+dfsg-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
libzstd
bionic
not-affected
focal
not-affected
jammy
needed
kinetic
ignored
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
ignored
xenial
not-affected
openSUSE logo
openSUSE / SLES Releases
openSUSE Product
Release
libzstd-devel
suse enterprise desktop 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise desktop 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise desktop 15 SP7
1.5.7-150700.1.2
fixed
suse enterprise sap 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise sap 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise sap 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise sap 15 SP7
1.5.7-150700.1.2
fixed
suse enterprise server 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise server 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise server 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise server 15 SP7
1.5.7-150700.1.2
fixed
libzstd1
suse enterprise desktop 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise desktop 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise desktop 15 SP7
1.5.7-150700.1.2
fixed
suse enterprise sap 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise sap 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise sap 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise sap 15 SP7
1.5.7-150700.1.2
fixed
suse enterprise server 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise server 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise server 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise server 15 SP7
1.5.7-150700.1.2
fixed
libzstd1-32bit
suse enterprise desktop 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise desktop 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise desktop 15 SP7
1.5.7-150700.1.2
fixed
suse enterprise sap 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise sap 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise sap 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise sap 15 SP7
1.5.7-150700.1.2
fixed
suse enterprise server 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise server 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise server 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise server 15 SP7
1.5.7-150700.1.2
fixed
zstd
suse enterprise desktop 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise desktop 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise desktop 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise desktop 15 SP7
1.5.7-150700.1.2
fixed
suse enterprise sap 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise sap 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise sap 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise sap 15 SP7
1.5.7-150700.1.2
fixed
suse enterprise server 15 SP4
1.5.0-150400.3.3.1
fixed
suse enterprise server 15 SP5
1.5.0-150400.3.3.1
fixed
suse enterprise server 15 SP6
1.5.5-150600.1.3
fixed
suse enterprise server 15 SP7
1.5.7-150700.1.2
fixed
Red Hat logo
Red Hat Enterprise Linux Releases
Red Hat Product
Release
mysql
RHEL 9
0:8.0.36-1.el9_3
fixed
mysql-common
RHEL 9
0:8.0.36-1.el9_3
fixed
mysql-devel
RHEL 9
0:8.0.36-1.el9_3
fixed
mysql-errmsg
RHEL 9
0:8.0.36-1.el9_3
fixed
mysql-libs
RHEL 9
0:8.0.36-1.el9_3
fixed
mysql-server
RHEL 9
0:8.0.36-1.el9_3
fixed
mysql-test
RHEL 9
0:8.0.36-1.el9_3
fixed