CVE-2021-4048
Summary
| CVE | CVE-2021-4048 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-12-08 22:15:00 UTC |
| Updated | 2023-11-07 03:40:00 UTC |
| Description | An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| [SECURITY] Fedora 34 Update: lapack-3.9.0-7.fc34 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| stegr! call segfault · Issue #42415 · JuliaLang/julia · GitHub |
MISC |
github.com |
|
| Fix out of bounds read in ?llarv (Reference-LAPACK PR 625) · xianyi/OpenBLAS@337b651 · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 35 Update: lapack-3.10.0-4.fc35 - package-announce - Fedora Mailing-Lists |
|
lists.fedoraproject.org |
|
| Fix out of bounds read in slarrv by Keno · Pull Request #625 · Reference-LAPACK/lapack · GitHub |
MISC |
github.com |
|
| [SECURITY] Fedora 35 Update: lapack-3.10.0-4.fc35 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Merge pull request #625 from JuliaComputing/kf/slarrvbounds · Reference-LAPACK/lapack@38f3eee · GitHub |
MISC |
github.com |
|
| 2024358 – (CVE-2021-4048) CVE-2021-4048 lapack: Out-of-bounds read in *larrv |
MISC |
bugzilla.redhat.com |
|
| [SECURITY] Fedora 34 Update: lapack-3.9.0-7.fc34 - package-announce - Fedora Mailing-Lists |
FEDORA |
lists.fedoraproject.org |
|
| Fix out of bounds read in ?llarv (Reference-LAPACK PR 625) · xianyi/OpenBLAS@ddb0ff5 · GitHub |
MISC |
github.com |
|
| Fix out of bounds read in ?llarv (Reference-LAPACK PR 625) · xianyi/OpenBLAS@fe497ef · GitHub |
MISC |
github.com |
|
| Fix out of bounds read in ?llarv (Reference-LAPACK PR 625) · xianyi/OpenBLAS@2be5ee3 · GitHub |
MISC |
github.com |
|
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 160230 Oracle Enterprise Linux Security Update for openblas (ELSA-2022-7639)
- 184201 Debian Security Update for lapackopenblas (CVE-2021-4048)
- 20270 Oracle Database 21c Critical Patch Update - October 2022
- 240844 Red Hat Update for openblas (RHSA-2022:7639)
- 282174 Fedora Security Update for lapack (FEDORA-2021-0d4b58060d)
- 282175 Fedora Security Update for lapack (FEDORA-2021-aec9d01057)
- 354376 Amazon Linux Security Advisory for lapack : ALAS2022-2022-173
- 354484 Amazon Linux Security Advisory for lapack : ALAS2022-2022-029
- 357019 Amazon Linux Security Advisory for openblas : ALAS2R4-2023-001
- 671358 EulerOS Security Update for lapack (EulerOS-SA-2022-1272)
- 671363 EulerOS Security Update for lapack (EulerOS-SA-2022-1299)
- 671369 EulerOS Security Update for openblas (EulerOS-SA-2022-1316)
- 671385 EulerOS Security Update for lapack (EulerOS-SA-2022-1315)
- 671386 EulerOS Security Update for openblas (EulerOS-SA-2022-1300)
- 671499 EulerOS Security Update for lapack (EulerOS-SA-2022-1476)
- 671525 EulerOS Security Update for lapack (EulerOS-SA-2022-1467)
- 671530 EulerOS Security Update for openblas (EulerOS-SA-2022-1469)
- 671534 EulerOS Security Update for openblas (EulerOS-SA-2022-1478)
- 671690 EulerOS Security Update for lapack (EulerOS-SA-2022-1736)
- 751906 SUSE Enterprise Linux Security Update for lapack (SUSE-SU-2022:0913-1)
- 751914 OpenSUSE Security Update for lapack (openSUSE-SU-2022:0915-1)
- 751990 SUSE Enterprise Linux Security Update for lapack (SUSE-SU-2022:0915-1)
- 900340 Common Base Linux Mariner (CBL-Mariner) Security Update for lapack (6300)
- 901171 Common Base Linux Mariner (CBL-Mariner) Security Update for lapack (6609-1)
- 901980 Common Base Linux Mariner (CBL-Mariner) Security Update for openblas (7315)
- 904153 Common Base Linux Mariner (CBL-Mariner) Security Update for openblas (7315-1)
- 940752 AlmaLinux Security Update for openblas (ALSA-2022:7639)
- 960398 Rocky Linux Security Update for openblas (RLSA-2022:7639)