Vulnerability Intelligence Report
CVE-2021-3520
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
EPSS Probability:3.22%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-190 ↗CWE-190->CWE-787
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| lz4_project | lz4 | all |
| netapp | active_iq_unified_manager | all |
| netapp | cloud_backup | all |
| netapp | ontap_select_deploy_administration_utility | all |
| oracle | communications_cloud_native_core_policy | 1.14.0 |
| oracle | zfs_storage_appliance_kit | 8.8 |
| splunk | universal_forwarder | 9.1.0 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
3.216%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2021-04-28T00:00:00 |
| Published | 2021-06-02T12:32:32 |
| Last Updated | 2024-08-03T17:01:07 |
Community Chatter & Buzz