yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2022-4899
Component Overview
Vulnerability Overview
Name
CVE-2022-4899
Source
NVD (
link
)
Debian (
link
)
Description
A vulnerability was found in zstd v1.4.10, where an attacker can supply empty string as an argument to the command line tool to cause buffer overrun.
CWEs
CWE-400
CWE-400
CWE-400
Published Date
Mar 31, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/facebook/zstd/issues/3200
Issue Tracking
https://github.com/facebook/zstd/issues/3200
Issue Tracking
Analysis
#
Affected Component
Analysis
zstd
Patched
Vulnerability Ratings
#
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
zstd
buildroot
2025.02.x
1.5.7
Not Affected
zstd
buildroot
master
1.5.7
Not Affected
zstd
openwrt
master
1.5.7-r1
Not Affected
zstd
openwrt
openwrt-25.12
1.5.7-r1
Not Affected
zstd
yocto
master
1.5.7
Not Affected
zstd
yocto
scarthgap
1.5.5
Not Affected
Resolved with patches
#
zstd (yocto:kirkstone)
#
Title
Author
Resolve
1
Disallow empty output directory
Elliot Gorokhovsky <embg@fb.com>
CVE-2022-4899
2
Fix buffer underflow for null dir1
Elliot Gorokhovsky <embg@fb.com>
CVE-2022-4899