PT-2021-4581 · Lz4+9 · Lz4+9

Published

2019-04-24

·

Updated

2025-02-11

·

CVE-2021-3520

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions lz4 (affected versions not specified)
Description The issue is related to an integer overflow in lz4, which can be triggered by submitting a crafted file to an application linked with lz4. This overflow leads to calling memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well. An attacker may be able to exploit this flaw to gain access to confidential data, disrupt their integrity, and cause a denial of service using a specially crafted file.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Integer Overflow

Memory Corruption

Weakness Enumeration

Related Identifiers

ALSA-2021:2575
ALT-PU-2019-1717
ALT-PU-2024-8898
ALT-PU-2025-2423
AZL-74241
BDU:2021-05259
CESA-2021_2575
CVE-2021-3520
DLA-2657-1
DSA-4919-1
MGASA-2021-0229
OESA-2021-1245
OPENSUSE-SU-2021:0760-1
OPENSUSE-SU-2021:1825-1
OPENSUSE-SU-2021_0760-1
OPENSUSE-SU-2021_1825-1
OPENSUSE-SU-2024:11562-1
OPENSUSE-SU-2024:12902-1
RHSA-2021:2575
RHSA-2021_2575
RLSA-2021:2575
RUSTSEC-2022-0051
SUSE-SU-2021:1613-1
SUSE-SU-2021:1647-1
SUSE-SU-2021:1825-1
SUSE-SU-2021_1647-1
SUSE-SU-2021_1825-1
USN-4968-1
USN-4968-2

Affected Products

Alt Linux
Almalinux
Astra Linux
Centos
Linuxmint
Red Hat
Rocky Linux
Suse
Ubuntu
Lz4