CVE-2021-4048 is a critical out-of-bounds read vulnerability affecting the CLARRV, DLARRV, SLARRV, and ZLARRV functions in LAPACK up to version 3.10.0, and OpenBLAS before 0.3.18, impacting products from Fedora, JuliaLang, LAPACK Project, OpenBLAS Project, and Red Hat. This flaw, rated 9.1 CRITICAL (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H), allows unauthenticated remote attackers to cause application crashes or potentially disclose memory contents with low attack complexity. Despite its high severity, there is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.10.0CPE matchmatch criteria | cpe:2.3:a:lapack_project:lapack:*:*:*:*:*:*:*:* | ||
< 0.3.18CPE matchmatch criteria | cpe:2.3:a:openblas_project:openblas:*:*:*:*:*:*:*:* | ||
<= 1.6.3CPE matchmatch criteria | cpe:2.3:a:julialang:julia:*:*:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:julialang:julia:1.7.0:beta1:*:*:*:*:*:* | ||
1.7.0CPE matchmatch criteria | cpe:2.3:a:julialang:julia:1.7.0:beta2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
An out-of-bounds read flaw was found in the CLARRV DLARRV SLARRV and ZLARRV functions in lapack through version 3.10.0 as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.
Dec 14, 2021lapack: Out-of-bounds read in *larrv
Sep 30, 2021