Buffer overflow in Zstandard - CVE-2022-4899
Published: March 30, 2023
Vulnerability identifier: #VU74201
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-4899
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in util.c when processing empty arguments in the command line tool. A remote attacker can pass an empty string as an argument, trigger buffer underflow and crash the application.
Affected software
Zstandard
Amazon Linux AMI
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Oracle Solaris
Basesystem Module
openSUSE Leap
openEuler
Fedora
Guardium Data Security Center (GDSC)
ObjectScale
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Oracle SD-WAN Edge
MySQL Server
MySQL Connectors
MySQL Cluster
mecab
zstd-debugsource
libzstd1
libzstd1-debuginfo
zstd
zstd-debuginfo
libzstd1-32bit
libzstd1-32bit-debuginfo
libzstd-devel
zstd-devel
zstd-help
libzstd-devel-32bit
libzstd-devel-static
mingw-zstd
mecab-ipadic
mecab-ipadic-EUCJP
community-mysql
rh-mysql80-mysql (Red Hat package)
mysql (Red Hat package)
mysql
mysql-common
mysql-devel
mysql-errmsg
mysql-libs
mysql-server
mysql-test
AMQ Streams
Amazon Linux AMI
SUSE Linux Enterprise Real Time 15
SUSE Linux Enterprise Desktop 15
SUSE Linux Enterprise High Performance Computing 15
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Server for SAP Applications 15
SUSE Manager Server
SUSE Manager Retail Branch Server
SUSE Manager Proxy
SUSE Linux Enterprise Micro
SUSE Linux Enterprise Micro for Rancher
openSUSE Leap Micro
Anolis OS
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Oracle Solaris
Basesystem Module
openSUSE Leap
openEuler
Fedora
Guardium Data Security Center (GDSC)
ObjectScale
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data
Oracle SD-WAN Edge
MySQL Server
MySQL Connectors
MySQL Cluster
mecab
zstd-debugsource
libzstd1
libzstd1-debuginfo
zstd
zstd-debuginfo
libzstd1-32bit
libzstd1-32bit-debuginfo
libzstd-devel
zstd-devel
zstd-help
libzstd-devel-32bit
libzstd-devel-static
mingw-zstd
mecab-ipadic
mecab-ipadic-EUCJP
community-mysql
rh-mysql80-mysql (Red Hat package)
mysql (Red Hat package)
mysql
mysql-common
mysql-devel
mysql-errmsg
mysql-libs
mysql-server
mysql-test
AMQ Streams
How to mitigate CVE-2022-4899
Install updates from vendor's website.
Zstandard - update to 1.5.4
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.0
MySQL Server - update to 8.0.34
MySQL Cluster - update to 8.0.34
mecab - update to 0.996-2
ObjectScale - update to 1.4.0
zstd-debugsource - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1 - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1-debuginfo - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
zstd - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
zstd-debuginfo - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1-32bit - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1-32bit-debuginfo - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd-devel - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
zstd-debuginfo - update to 1.5.0-4
zstd-debugsource - update to 1.5.0-4
zstd-devel - update to 1.5.0-4
zstd - update to 1.5.0-4
zstd-help - update to 1.5.0-4
libzstd-devel-32bit - update to 1.5.0-150400.3.3.1
libzstd-devel-static - update to 1.5.0-150400.3.3.1
zstd - update to 1.5.2-1
mingw-zstd - addressed in versions 1.5.4-1.fc36, 1.5.4-1.fc37, 1.5.4-1.fc38
AMQ Streams - update to 2.7.0
mecab-ipadic - update to 2.7.0.20070801-16.0.1
mecab-ipadic-EUCJP - update to 2.7.0.20070801-16.0.1
community-mysql - addressed in versions 8.0.34-2.fc37, 8.0.34-2.fc38, 8.0.34-2.fc39
rh-mysql80-mysql (Red Hat package) - update to 8.0.36-1.el7
mysql (Red Hat package) - update to 8.0.36-1.el9_3
mysql - update to 8.0.36-1.0.1
mysql-common - update to 8.0.36-1.0.1
mysql-devel - update to 8.0.36-1.0.1
mysql-errmsg - update to 8.0.36-1.0.1
mysql-libs - update to 8.0.36-1.0.1
mysql-server - update to 8.0.36-1.0.1
mysql-test - update to 8.0.36-1.0.1
mysql - addressed in versions 8.0-3720230907003352.9e842022, 8.0-3820230907003352.75741a8b
Guardium Data Security Center (GDSC) - update to 3.6.1
IBM Watson Speech Services Cartridge for IBM Cloud Pak for Data - update to 5.2.0
MySQL Server - update to 8.0.34
MySQL Cluster - update to 8.0.34
mecab - update to 0.996-2
ObjectScale - update to 1.4.0
zstd-debugsource - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1 - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1-debuginfo - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
zstd - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
zstd-debuginfo - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1-32bit - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd1-32bit-debuginfo - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
libzstd-devel - addressed in versions 1.4.4-150000.1.9.1, 1.5.0-150400.3.3.1
zstd-debuginfo - update to 1.5.0-4
zstd-debugsource - update to 1.5.0-4
zstd-devel - update to 1.5.0-4
zstd - update to 1.5.0-4
zstd-help - update to 1.5.0-4
libzstd-devel-32bit - update to 1.5.0-150400.3.3.1
libzstd-devel-static - update to 1.5.0-150400.3.3.1
zstd - update to 1.5.2-1
mingw-zstd - addressed in versions 1.5.4-1.fc36, 1.5.4-1.fc37, 1.5.4-1.fc38
AMQ Streams - update to 2.7.0
mecab-ipadic - update to 2.7.0.20070801-16.0.1
mecab-ipadic-EUCJP - update to 2.7.0.20070801-16.0.1
community-mysql - addressed in versions 8.0.34-2.fc37, 8.0.34-2.fc38, 8.0.34-2.fc39
rh-mysql80-mysql (Red Hat package) - update to 8.0.36-1.el7
mysql (Red Hat package) - update to 8.0.36-1.el9_3
mysql - update to 8.0.36-1.0.1
mysql-common - update to 8.0.36-1.0.1
mysql-devel - update to 8.0.36-1.0.1
mysql-errmsg - update to 8.0.36-1.0.1
mysql-libs - update to 8.0.36-1.0.1
mysql-server - update to 8.0.36-1.0.1
mysql-test - update to 8.0.36-1.0.1
mysql - addressed in versions 8.0-3720230907003352.9e842022, 8.0-3820230907003352.75741a8b
External References
Related Security Bulletins
- Denial of service in Facebook Zstandard
- SUSE update for zstd
- SUSE update for zstd
- Multiple vulnerabilities in MySQL Server
- Buffer overflow in MySQL Connectors
- Multiple vulnerabilities in MySQL Cluster
- Fedora 36 update for mingw-zstd
- Fedora 37 update for mingw-zstd
- Fedora 38 update for mingw-zstd
- Multiple vulnerabilities in Oracle Solaris third-party software
- Fedora 37 update for community-mysql
- Fedora 39 update for community-mysql
- Fedora 38 update for community-mysql
- Fedora 37 Modular update for mysql
- Fedora 38 Modular update for mysql
- Multiple vulnerabilities in Oracle SD-WAN Edge
- Red Hat Enterprise Linux 8 update for the mysql:8.0 module
- openEuler 22.03 LTS SP1 update for zstd
- openEuler 22.03 LTS update for zstd
- Red Hat Enterprise Linux 9 update for mysql
- Red Hat Software Collections update for rh-mysql80-mysql
- Multiple vulnerabilities in AMQ Streams 2.7
- Multiple vulnerabilities in Dell ObjectScale
- Multiple vulnerabilities in Guardium Data Security Center
- Amazon Linux AMI update for zstd
- Anolis OS update for mysql:8.0 module
- Multiple vulnerabilities in IBM Watson Speech Services Cartridge