Critical severity9.8NVD Advisory· Published Jun 2, 2021· Updated Jun 17, 2026
CVE-2021-3520
CVE-2021-3520
Description
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
34- cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:*
- cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
- cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:*
- cpe:2.3:a:oracle:zfs_storage_appliance_kit:8.8:*:*:*:*:*:*:*
cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:splunk:universal_forwarder:*:*:*:*:*:*:*:*range: >=8.2.0,<8.2.12
- cpe:2.3:a:splunk:universal_forwarder:9.1.0:*:*:*:*:*:*:*
- lz4/lz4description
- osv-coords24 versionspkg:rpm/almalinux/lz4pkg:rpm/almalinux/lz4-develpkg:rpm/almalinux/lz4-libspkg:rpm/opensuse/lz4&distro=openSUSE%20Leap%2015.2pkg:rpm/opensuse/lz4&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/lz4&distro=openSUSE%20Tumbleweedpkg:rpm/opensuse/lz4-test&distro=openSUSE%20Leap%2015.2pkg:rpm/suse/lz4&distro=SUSE%20Enterprise%20Storage%206pkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-ESPOSpkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015%20SP1-LTSSpkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-ESPOSpkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20High%20Performance%20Computing%2015-LTSSpkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20Micro%205.0pkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP2pkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-BCLpkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20Server%2015%20SP1-LTSSpkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20Server%2015-LTSSpkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015pkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2015%20SP1pkg:rpm/suse/lz4&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5pkg:rpm/suse/lz4&distro=SUSE%20Manager%20Proxy%204.0pkg:rpm/suse/lz4&distro=SUSE%20Manager%20Retail%20Branch%20Server%204.0pkg:rpm/suse/lz4&distro=SUSE%20Manager%20Server%204.0
< 1.8.3-3.el8_4+ 23 more
- (no CPE)range: < 1.8.3-3.el8_4
- (no CPE)range: < 1.8.3-3.el8_4
- (no CPE)range: < 1.8.3-3.el8_4
- (no CPE)range: < 1.8.0-lp152.5.3.1
- (no CPE)range: < 1.9.2-3.3.1
- (no CPE)range: < 1.9.3-2.1
- (no CPE)range: < 1.8.0-lp152.5.3.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.9.2-3.3.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.3.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
- (no CPE)range: < 1.8.0-3.8.1
Patches
Vulnerability mechanics
References
5- bugzilla.redhat.com/show_bug.cginvdIssue TrackingPatchThird Party Advisory
- www.oracle.com//security-alerts/cpujul2021.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party Advisory
- www.oracle.com/security-alerts/cpuoct2021.htmlnvdPatchThird Party Advisory
- security.netapp.com/advisory/ntap-20211104-0005/nvdThird Party Advisory
News mentions
0No linked articles in our index yet.