« List of all CVEs

CVE-2021-3520

Published: 6/2/2021 Last updated: 8/3/2024 Reserved: 4/28/2021

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

CNA assigner: redhat (53f830b8-0a3f-465b-8143-3b8a9948e749) Requested by: n/a

Opam packages affected (2)

conf-liblz4 conf-lz4

Products affected (1)

Product Vendor Version
lz4 n/a n/a

References (10)