CVE-2014-4715 is misclassified (by our CVE tracker) as affecting version 1.9.2, while in fact this issue has been fixed since lz4-r130: https://github.com/lz4/lz4/commit/140e6e72ddb6fc5f7cd28ce0c8ec3812ef4a9c08 See https://github.com/lz4/lz4/issues/818 Signed-off-by: Fabrice Fontaine <fontaine.fabrice@gmail.com> Signed-off-by: Thomas Petazzoni <thomas.petazzoni@bootlin.com>