yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2023-46228
Component Overview
Vulnerability Overview
Name
CVE-2023-46228
Source
NVD (
link
)
Debian (
link
)
Description
zchunk before 1.3.2 has multiple integer overflows via malformed zchunk files to lib/comp/comp.c, lib/comp/zstd/zstd.c, lib/dl/multipart.c, or lib/header.c.
CWEs
CWE-190
Published Date
Oct 19, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://bugzilla.suse.com/show_bug.cgi?id=1216268
Issue Tracking
https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe
Patch
https://github.com/zchunk/zchunk/compare/1.3.1...1.3.2
Patch
https://bugzilla.suse.com/show_bug.cgi?id=1216268
Issue Tracking
https://github.com/zchunk/zchunk/commit/08aec2b4dfd7f709b6e3d511411ffcc83ed4efbe
Patch
https://github.com/zchunk/zchunk/compare/1.3.1...1.3.2
Patch
Analysis
#
Affected Component
Analysis
zchunk
Patched
Vulnerability Ratings
#
7.8
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
zchunk
buildroot
2025.02.x
1.3.2
Not Affected
zchunk
buildroot
master
1.3.2
Not Affected
zchunk
yocto
master
1.5.3
Not Affected
zchunk
yocto
scarthgap
1.4.0
Not Affected
Resolved with patches
#
zchunk (yocto:kirkstone)
#
Title
Author
Resolve
1
Handle overflow errors in malformed zchunk files
Jonathan Dieter <jdieter@gmail.com>
CVE-2023-46228