First published: Wed Apr 28 2021(Updated: )
lz4 could allow a remote attacker to execute arbitrary code on the system, caused by an integer overflow. By sending a specially crafted file, an attacker could invoke memmove() on a negative size argument leading to memory corruption and trigger an out-of-bounds write or cause the library to crash.
Credit: secalert@redhat.com secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/lz4 | <0:1.8.3-3.el8_4 | 0:1.8.3-3.el8_4 |
redhat/lz4 | <1.9.4 | 1.9.4 |
IBM Security Verify Access | <=10.0.0 | |
LZ4 | =1.8.3 | |
NetApp Active IQ Unified Manager for VMware vSphere | ||
NetApp ONTAP Select Deploy | ||
oracle communications Cloud native core policy | =1.14.0 | |
Oracle Sun ZFS Storage Appliance Kit | =8.8 | |
LZ4 | >=1.8.3<1.9.4 | |
netapp cloud backup | ||
Splunk Universal Forwarder | >=8.2.0<8.2.12 | |
Splunk Universal Forwarder | >=9.0.0<9.0.6 | |
Splunk Universal Forwarder | =9.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Appears in the following advisories)
CVE-2021-3520 is a vulnerability in lz4 that allows a remote attacker to execute arbitrary code on the system.
CVE-2021-3520 can lead to an out-of-bounds write and/or a crash, impacting the availability of the system.
The affected software includes lz4 versions up to 1.9.4 and IBM Security Verify Access up to version 10.0.0.
Yes, updating lz4 to version 1.9.4 or higher resolves CVE-2021-3520.
More information about CVE-2021-3520 can be found in the references: [link1], [link2], [link3].