| Vulnerability Name: | CVE-2021-4048 (CCN-215061) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Assigned: | 2021-09-30 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Published: | 2021-09-30 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Updated: | 2022-01-04 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Summary: | An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| CVSS v3 Severity: | 9.1 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H) 7.9 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
7.9 High (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:C)
5.2 Medium (REDHAT Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Vulnerability Type: | CWE-125 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Vulnerability Consequences: | Denial of Service | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2021-4048 Source: XF Type: UNKNOWN netlib-cve20214048-dos(215061) Source: CCN Type: julia GIT Repository stegr! call segfault #42415 Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://github.com/JuliaLang/julia/issues/42415 Source: MISC Type: Patch, Third Party Advisory https://github.com/Reference-LAPACK/lapack/commit/38f3eeee3108b18158409ca2a100e6fe03754781 Source: CCN Type: lapack GIT Repository Fix out of bounds read in slarrv #625 Source: MISC Type: Issue Tracking, Patch, Third Party Advisory https://github.com/Reference-LAPACK/lapack/pull/625 Source: MISC Type: Patch, Third Party Advisory https://github.com/xianyi/OpenBLAS/commit/2be5ee3cca97a597f2ee2118808a2d5eacea050c Source: MISC Type: Patch, Third Party Advisory https://github.com/xianyi/OpenBLAS/commit/337b65133df174796794871b3988cd03426e6d41 Source: MISC Type: Patch, Third Party Advisory https://github.com/xianyi/OpenBLAS/commit/ddb0ff5353637bb5f5ad060c9620e334c143e3d7 Source: MISC Type: Patch, Third Party Advisory https://github.com/xianyi/OpenBLAS/commit/fe497efa0510466fd93578aaf9da1ad8ed4edbe7 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-aec9d01057 Source: FEDORA Type: Mailing List, Third Party Advisory FEDORA-2021-0d4b58060d | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Vulnerable Configuration: | Configuration 1: Configuration 2: Configuration 3: Configuration 4: Configuration 5: Configuration RedHat 1: Configuration RedHat 2: Configuration RedHat 3: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| BACK | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||||