CVE-2019-11934

Source
https://cve.org/CVERecord?id=CVE-2019-11934
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11934.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2019-11934
Published
2019-12-04T17:16:43.180Z
Modified
2026-04-11T08:55:49.735988Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Improper handling of close_notify alerts can result in an out-of-bounds read in AsyncSSLSocket. This issue affects folly prior to v2019.11.04.00.

References

Affected packages

Git / github.com/facebook/folly

Affected ranges

Type
GIT
Repo
https://github.com/facebook/folly
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
{
    "versions": [
        {
            "introduced": "0"
        },
        {
            "fixed": "2019.11.04.00"
        }
    ]
}

Affected versions

2016.*
2016.07.26
Other
deprecate-dynamic-initializer
v0.*
v0.22.0
v0.23.0
v0.24.0
v0.25.0
v0.26.0
v0.27.0
v0.28.0
v0.29.0
v0.30.0
v0.31.0
v0.32.0
v0.33.0
v0.34.0
v0.35.0
v0.36.0
v0.37.0
v0.38.0
v0.39.0
v0.40.0
v0.41.0
v0.42.0
v0.43.0
v0.45.0
v0.47.0
v0.48.0
v0.49.0
v0.49.1
v0.50.0
v0.51.0
v0.52.0
v0.53.0
v0.54.0
v0.55.0
v0.56.0
v0.57.0
v2016.*
v2016.07.29.00
v2016.08.01.00
v2016.08.08.00
v2016.08.15.00
v2016.08.22.00
v2016.08.29.00
v2016.09.05.00
v2016.09.12.00
v2016.09.12.01
v2016.09.19.00
v2016.09.26.00
v2016.10.03.00
v2016.10.10.00
v2016.10.17.00
v2016.10.24.00
v2016.10.31.00
v2016.11.07.00
v2016.11.14.00
v2016.11.21.00
v2016.11.28.00
v2016.12.05.00
v2016.12.12.00
v2016.12.19.00
v2017.*
v2017.03.06.00
v2017.03.13.00
v2017.03.20.00
v2017.03.27.00
v2017.04.03.00
v2017.04.10.00
v2017.04.17.00
v2017.04.24.00
v2017.05.01.00
v2017.05.08.00
v2017.05.15.00
v2017.05.22.00
v2017.05.29.00
v2017.06.05.00
v2017.06.12.00
v2017.06.19.00
v2017.06.26.00
v2017.06.26.01
v2017.07.03.00
v2017.07.10.00
v2017.07.17.00
v2017.07.17.01
v2017.07.24.00
v2017.07.31.00
v2017.08.07.00
v2017.08.14.00
v2017.08.21.00
v2017.08.28.00
v2017.09.04.00
v2017.09.11.00
v2017.09.18.00
v2017.09.25.00
v2017.10.02.00
v2017.10.09.00
v2017.10.16.00
v2017.10.23.00
v2017.10.30.00
v2017.11.06.00
v2017.11.13.00
v2017.11.20.00
v2017.11.27.00
v2017.12.04.00
v2017.12.11.00
v2017.12.18.00
v2017.12.25.00
v2018.*
v2018.01.01.00
v2018.01.08.00
v2018.01.15.00
v2018.01.22.00
v2018.01.29.00
v2018.02.05.00
v2018.02.12.00
v2018.02.19.00
v2018.02.26.00
v2018.03.05.00
v2018.03.12.00
v2018.03.19.00
v2018.03.26.00
v2018.04.02.00
v2018.04.09.00
v2018.04.16.00
v2018.04.23.00
v2018.04.30.00
v2018.05.07.00
v2018.05.14.00
v2018.05.21.00
v2018.05.28.00
v2018.06.04.00
v2018.06.11.00
v2018.06.18.00
v2018.06.25.00
v2018.07.02.00
v2018.07.09.00
v2018.07.16.00
v2018.07.23.00
v2018.07.30.00
v2018.08.06.00
v2018.08.09.00
v2018.08.13.00
v2018.08.20.00
v2018.08.27.00
v2018.09.03.00
v2018.09.03.01
v2018.09.10.00
v2018.09.10.01
v2018.09.17.00
v2018.09.24.00
v2018.10.01.00
v2018.10.08.00
v2018.10.15.00
v2018.10.22.00
v2018.10.29.00
v2018.11.05.00
v2018.11.12.00
v2018.11.19.00
v2018.11.26.00
v2018.12.03.00
v2018.12.10.00
v2018.12.17.00
v2018.12.24.00
v2018.12.31.00
v2019.*
v2019.01.07.00
v2019.01.14.00
v2019.01.21.00
v2019.01.28.00
v2019.02.04.00
v2019.02.11.00
v2019.02.18.00
v2019.02.25.00
v2019.03.04.00
v2019.03.18.00
v2019.03.25.00
v2019.04.01.00
v2019.04.08.00
v2019.04.15.00
v2019.04.22.00
v2019.04.29.00
v2019.05.06.00
v2019.05.13.00
v2019.05.20.00
v2019.05.27.00
v2019.06.03.00
v2019.06.10.00
v2019.06.17.00
v2019.07.22.00
v2019.07.29.00
v2019.08.05.00
v2019.08.12.00
v2019.08.19.00
v2019.08.26.00
v2019.09.02.00
v2019.09.09.00
v2019.09.16.00
v2019.09.23.00
v2019.09.30.00
v2019.10.07.00
v2019.10.14.00
v2019.10.21.00
v2019.10.28.00

Database specific

vanir_signatures_modified
"2026-04-11T08:55:49Z"
source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2019-11934.json"
vanir_signatures
[
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "227842235891407263626649147242593756560",
                "92515533098277077246808838987096168480",
                "41501300739345054074027572364971077221"
            ]
        },
        "target": {
            "file": "folly/io/async/test/AsyncSSLSocketTest.cpp"
        },
        "signature_type": "Line",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2019-11934-15cae1b6",
        "source": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "261231623053436505095871506781012096601",
                "286914380897518449386451780316609904063",
                "263691185398388655486092779676898764002",
                "326474520797465923553052603047275735429",
                "192217701151701571741875830885652858858",
                "140367133316138761799266409257270038774",
                "94769172400256801600095857208904409484",
                "35328760388702852149373658704921178573",
                "220812273434447138889752611393783581409",
                "318701462258712987432826633087165889433",
                "272572454045733329725797367297703215423",
                "38227911922413227573051712062649436206",
                "51965793703870531308777205517947936655",
                "222624100566249721514793820578262468064",
                "78102301785476049628187294871728916688",
                "206369248006594848080543616108648787962",
                "37977686660821760226397397307693473247",
                "265408800696192563652483532500518291086",
                "328879499561668478406530140773754096355",
                "296467721838758480180215138707527552132",
                "58112408689369985417923340916678058732",
                "284208982872406563419208703844503064754",
                "18844935139490207353426559352691032148",
                "296772127511026077243167009336814543965",
                "97620082593581042468667859131869171387"
            ]
        },
        "target": {
            "file": "folly/functional/Invoke.h"
        },
        "signature_type": "Line",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2019-11934-1f9c79c4",
        "source": "https://github.com/facebook/folly/commit/05490a16e98b2b7c4857d39b2c2b9d89f33a5b1d"
    },
    {
        "digest": {
            "length": 2886.0,
            "function_hash": "152049047512235869806428153343173593161"
        },
        "target": {
            "file": "folly/io/async/AsyncSSLSocket.cpp",
            "function": "AsyncSSLSocket::performWrite"
        },
        "signature_type": "Function",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2019-11934-758d6fc6",
        "source": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "91174101857615857246751717836782017619",
                "224397719918820131799092403530216005212",
                "110074145152088808578488804447035882284",
                "205537247213205996188687327878743244821"
            ]
        },
        "target": {
            "file": "folly/io/async/test/AsyncSSLSocketTest.h"
        },
        "signature_type": "Line",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2019-11934-7b897f9f",
        "source": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "332172897470950106032031387980330282491",
                "196357949611617615121387290494035456414",
                "163806642041932125357015027133177103641",
                "149183718398152353674872717866950952724",
                "314391746119481296618640393529490021139",
                "130905895901032801339097811874714432573",
                "316704988141788863683152317069983874072",
                "169319633626666584499412075480377734466",
                "297321755604719307018461840156548125399"
            ]
        },
        "target": {
            "file": "folly/functional/test/InvokeTest.cpp"
        },
        "signature_type": "Line",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2019-11934-95ac9a2f",
        "source": "https://github.com/facebook/folly/commit/05490a16e98b2b7c4857d39b2c2b9d89f33a5b1d"
    },
    {
        "digest": {
            "length": 916.0,
            "function_hash": "226764733386146705970750092482506010766"
        },
        "target": {
            "file": "folly/io/async/AsyncSSLSocket.cpp",
            "function": "AsyncSSLSocket::interpretSSLError"
        },
        "signature_type": "Function",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2019-11934-da104a4d",
        "source": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee"
    },
    {
        "digest": {
            "threshold": 0.9,
            "line_hashes": [
                "75437057547293670865545316756462918993",
                "248490720566392302503301509476307803515",
                "225147749680642770137217126037952714602",
                "81768500371893478651694426530049309823",
                "241293062028868454232575807199260944807",
                "72012039228958005014011165386187543026",
                "71947813208397625691021693678466393605",
                "289019617435022390838770355908762110945",
                "178404125538460680333652335649950667292",
                "227353430085061521589903766563349283893",
                "201703756875948512759860003072909010326",
                "99817092843894329774962665118647550387",
                "105472108802852616133169234456880531832"
            ]
        },
        "target": {
            "file": "folly/io/async/AsyncSSLSocket.cpp"
        },
        "signature_type": "Line",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2019-11934-da75beb9",
        "source": "https://github.com/facebook/folly/commit/c321eb588909646c15aefde035fd3133ba32cdee"
    },
    {
        "digest": {
            "length": 388.0,
            "function_hash": "37303251660540864891066728694050700195"
        },
        "target": {
            "file": "folly/functional/test/InvokeTest.cpp",
            "function": "TEST_F"
        },
        "signature_type": "Function",
        "signature_version": "v1",
        "deprecated": false,
        "id": "CVE-2019-11934-f6ce303b",
        "source": "https://github.com/facebook/folly/commit/05490a16e98b2b7c4857d39b2c2b9d89f33a5b1d"
    }
]