The Lz4 Project maintains a widely embedded data-compression library that appears in many applications and runtime environments despite its narrow product scope, making individual flaws potentially consequential across downstream consumers. The observed vulnerability pattern centers on memory-safety issues inherent to a high-performance C implementation, with recurring exposure to out-of-bounds writes and integer overflow conditions that reflect the buffer-handling demands of a compression codec. Current exploitation activity, severity distribution, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lz4 Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-3520CRITICAL There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a neg | Jun 2, 2021 | 9.8 | 32 | NO | NO |
CVE-2019-17543HIGH LZ4 before 1.9.2 has a heap-based buffer overflow in LZ4_write32 (related to LZ4_compress_destSize), affecting applications that call LZ4_compress_fast with a large input. (This is | Oct 14, 2019 | 8.1 | 30 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lz4 Project.
Media articles that mention a CVE ID that affects a product developed by Lz4 Project — matched by CVE ID, not by vendor name.