CVE-2021-3520

Source
https://cve.org/CVERecord?id=CVE-2021-3520
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3520.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2021-3520
Downstream
ALPINE (1)
AZL (1)
BELL (1)
CLSA (2)
DEBIAN (1)
JLSEC (1)
MGASA (1)
OESA (1)
openSUSE (4)
RHSA (1)
RLSA (1)
SUSE (3)
UBUNTU (1)
Related
Published
2021-06-02T13:15:13Z
Modified
2026-07-07T08:50:52Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

Database specific
{
    "unresolved_ranges":  [
        {
            "cpes":  [
                "cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "8.2.0"
                },
                {
                    "fixed":  "8.2.12"
                },
                {
                    "introduced":  "9.0.0"
                },
                {
                    "fixed":  "9.0.6"
                }
            ],
            "source":  "CPE_RANGE",
            "vendor_product":  "splunk:universal_forwarder"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "1.14.0"
                },
                {
                    "last_affected":  "1.14.0"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "oracle:communications_cloud_native_core_policy"
        },
        {
            "cpes":  [
                "cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "8.8"
                },
                {
                    "last_affected":  "8.8"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "oracle:zfs_storage_appliance_kit"
        },
        {
            "cpes":  [
                "cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*"
            ],
            "extracted_events":  [
                {
                    "introduced":  "9.1.0"
                },
                {
                    "last_affected":  "9.1.0"
                }
            ],
            "source":  "CPE_STRING",
            "vendor_product":  "splunk:universal_forwarder"
        }
    ]
}
References

Affected packages

Git / github.com/lz4/lz4

Affected ranges

Type
GIT
Repo
https://github.com/lz4/lz4
Events
Database specific
Show details
{
    "cpe":  "cpe:2.3:a:lz4_project:lz4:*:*:*:*:*:*:*:*",
    "extracted_events":  [
        {
            "introduced":  "1.8.3"
        },
        {
            "fixed":  "1.9.4"
        }
    ],
    "source":  "CPE_RANGE"
}

Affected versions

v1.*
v1.8.3
v1.9.0
v1.9.1
v1.9.3

Database specific

source
"https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2021-3520.json"