CVE-2021-3520 is a critical integer overflow vulnerability in the lz4 compression library, affecting products like NetApp, Oracle, and Splunk. An unauthenticated attacker can exploit this flaw remotely by submitting a specially crafted file, leading to an out-of-bounds write, system crash, and potential compromise of confidentiality and integrity. While rated with a CVSS score of 9.8 (Critical), there is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.8.3, < 1.9.4CPE matchmatch criteria | cpe:2.3:a:lz4_project:lz4:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:ontap_select_deploy_administration_utility:-:*:*:*:*:*:*:* | ||
1.14.0CPE matchmatch criteria | cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
August Third Party Package Updates in Splunk Universal Forwarder
Aug 30, 2023August 2023 Third Party Package Updates in Splunk Enterprise
Aug 30, 2023lz4: memory corruption due to an integer overflow bug caused by memmove argument
Apr 28, 2021