Critical severity9.1NVD Advisory· Published Dec 8, 2021· Updated Jun 17, 2026
CVE-2021-4048
CVE-2021-4048
Description
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
41cpe:2.3:a:julialang:julia:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:julialang:julia:*:*:*:*:*:*:*:*range: <=1.6.3
- cpe:2.3:a:julialang:julia:1.7.0:beta1:*:*:*:*:*:*
- cpe:2.3:a:julialang:julia:1.7.0:beta2:*:*:*:*:*:*
- cpe:2.3:a:julialang:julia:1.7.0:beta3:*:*:*:*:*:*
- cpe:2.3:a:julialang:julia:1.7.0:beta4:*:*:*:*:*:*
- cpe:2.3:a:julialang:julia:1.7.0:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ceph_storage:2.0:*:*:*:*:*:*:*+ 3 more
- cpe:2.3:a:redhat:ceph_storage:2.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ceph_storage:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:ceph_storage:5.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_container_storage:4.0:*:*:*:*:*:*:*
- cpe:2.3:a:redhat:openshift_data_foundation:4.0:*:*:*:*:*:*:*
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*
- lapack/lapackdescription
- Range: <=3.10.0
- osv-coords21 versionspkg:bitnami/openblaspkg:rpm/almalinux/openblaspkg:rpm/almalinux/openblas-Rblaspkg:rpm/almalinux/openblas-develpkg:rpm/almalinux/openblas-openmppkg:rpm/almalinux/openblas-openmp64pkg:rpm/almalinux/openblas-openmp64_pkg:rpm/almalinux/openblas-serial64pkg:rpm/almalinux/openblas-serial64_pkg:rpm/almalinux/openblas-staticpkg:rpm/almalinux/openblas-threadspkg:rpm/almalinux/openblas-threads64pkg:rpm/almalinux/openblas-threads64_pkg:rpm/opensuse/lapack&distro=openSUSE%20Leap%2015.3pkg:rpm/opensuse/lapack-man&distro=openSUSE%20Leap%2015.3pkg:rpm/suse/lapack&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Basesystem%2015%20SP3pkg:rpm/suse/lapack&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Development%20Tools%2015%20SP3pkg:rpm/suse/lapack&distro=SUSE%20Linux%20Enterprise%20Real%20Time%2015%20SP2pkg:rpm/suse/lapack&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP5pkg:rpm/suse/lapack&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP5pkg:rpm/suse/lapack&distro=SUSE%20Linux%20Enterprise%20Software%20Development%20Kit%2012%20SP5
< 0.3.18+ 20 more
- (no CPE)range: < 0.3.18
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 0.3.15-4.el8
- (no CPE)range: < 3.5.0-4.6.1
- (no CPE)range: < 3.5.0-4.6.1
- (no CPE)range: < 3.5.0-4.6.1
- (no CPE)range: < 3.5.0-4.6.1
- (no CPE)range: < 3.5.0-4.6.1
- (no CPE)range: < 3.5.0-3.9.1
- (no CPE)range: < 3.5.0-3.9.1
- (no CPE)range: < 3.5.0-3.9.1
Patches
Vulnerability mechanics
References
9- github.com/JuliaLang/julia/issues/42415nvdIssue TrackingPatchThird Party Advisory
- github.com/Reference-LAPACK/lapack/commit/38f3eeee3108b18158409ca2a100e6fe03754781nvdPatchThird Party Advisory
- github.com/Reference-LAPACK/lapack/pull/625nvdIssue TrackingPatchThird Party Advisory
- github.com/xianyi/OpenBLAS/commit/2be5ee3cca97a597f2ee2118808a2d5eacea050cnvdPatchThird Party Advisory
- github.com/xianyi/OpenBLAS/commit/337b65133df174796794871b3988cd03426e6d41nvdPatchThird Party Advisory
- github.com/xianyi/OpenBLAS/commit/ddb0ff5353637bb5f5ad060c9620e334c143e3d7nvdPatchThird Party Advisory
- github.com/xianyi/OpenBLAS/commit/fe497efa0510466fd93578aaf9da1ad8ed4edbe7nvdPatchThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QFEVOCUG2UXMVMFMTU4ONJVDEHY2LW2/nvd
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DROZM4M2QRKSD6FBO4BHSV2QMIRJQPHT/nvd
News mentions
0No linked articles in our index yet.