CVE-2021-3520
Summary
| CVE | CVE-2021-3520 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-02 13:15:00 UTC |
| Updated | 2024-03-27 16:12:00 UTC |
| Description | There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| 1954559 – (CVE-2021-3520) CVE-2021-3520 lz4: memory corruption due to an integer overflow bug caused by memmove argument |
MISC |
bugzilla.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Oracle Critical Patch Update Advisory - April 2022 |
MISC |
www.oracle.com |
|
| CVE-2021-3520 lz4 Vulnerability in NetApp Products | NetApp Product Security |
CONFIRM |
security.netapp.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Oracle Critical Patch Update Advisory - July 2021 |
N/A |
www.oracle.com |
|
| Oracle Critical Patch Update Advisory - October 2021 |
MISC |
www.oracle.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| Red Hat Customer Portal - Access to 24x7 support and knowledge |
MISC |
access.redhat.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 159288 Oracle Enterprise Linux Security Update for lz4 (ELSA-2021-2575)
- 178590 Debian Security Update for lz4 (DLA 2657-1)
- 178618 Debian Security Update for lz4 (DSA 4919-1)
- 178632 Debian Security Update for lz4 (DSA 4919-1)
- 179635 Debian Security Update for lz4 (CVE-2021-3520)
- 198387 Ubuntu Security Notification for LZ4 vulnerability (USN-4968-1)
- 20354 Oracle Database 19c Critical Patch Update - July 2023
- 20355 Oracle Database 21c Critical Patch Update - July 2023
- 20356 Oracle Database 19c Critical OJVM Patch Update - July 2023
- 239465 Red Hat Update for lz4 (RHSA-2021:2575)
- 296053 Oracle Solaris 11.4 Support Repository Update (SRU) 35.94.4 Missing (CPUJUL2021)
- 354329 Amazon Linux Security Advisory for lz4 : ALAS2022-2022-169
- 354372 Amazon Linux Security Advisory for lz4 : ALAS2022-2022-137
- 355122 Amazon Linux Security Advisory for lz4 : ALAS2023-2023-015
- 377421 Alibaba Cloud Linux Security Update for lz4 (ALINUX3-SA-2021:0049)
- 378599 Splunk Enterprise Third Party Package Updates for June (SVD-2023-0613)
- 378883 Splunk Enterprise August Third Party Package Updates (SVD-2023-0808)
- 500373 Alpine Linux Security Update for lz4
- 501753 Alpine Linux Security Update for lz4
- 504131 Alpine Linux Security Update for lz4
- 591406 Siemens SIMATIC S7-1500 CPU GNU/Linux subsystem Multiple Vulnerabilities (SSB-439005, ICSA-22-104-13)
- 670649 EulerOS Security Update for lz4 (EulerOS-SA-2021-2407)
- 670716 EulerOS Security Update for lz4 (EulerOS-SA-2021-2474)
- 670752 EulerOS Security Update for lz4 (EulerOS-SA-2021-2510)
- 670777 EulerOS Security Update for lz4 (EulerOS-SA-2021-2535)
- 670801 EulerOS Security Update for lz4 (EulerOS-SA-2021-2559)
- 730206 McAfee Web Gateway Multiple Vulnerabilities (WP-3792, WP-4003, WP-4021, WP-4058, WP-4067)
- 750011 SUSE Enterprise Linux Security Update for lz4 (SUSE-SU-2021:1613-1)
- 750021 SUSE Enterprise Linux Security Update for lz4 (SUSE-SU-2021:1647-1)
- 750092 SUSE Enterprise Linux Security Update for lz4 (SUSE-SU-2021:1825-1)
- 750198 OpenSUSE Security Update for lz4 (openSUSE-SU-2021:0760-1)
- 750794 OpenSUSE Security Update for lz4 (openSUSE-SU-2021:1825-1)
- 904839 Common Base Linux Mariner (CBL-Mariner) Security Update for fluent-bit (12326)
- 904851 Common Base Linux Mariner (CBL-Mariner) Security Update for librdkafka (12357)
- 904898 Common Base Linux Mariner (CBL-Mariner) Security Update for lz4 (12361)
- 904992 Common Base Linux Mariner (CBL-Mariner) Security Update for lz4 (12561)
- 940325 AlmaLinux Security Update for lz4 (ALSA-2021:2575)
- 960088 Rocky Linux Security Update for lz4 (RLSA-2021:2575)