CVE-2021-4048
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.64%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- EPSS
- 2.64% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-125
- Affected
- lapack project/lapack · openblas project/openblas · julialang/julia · redhat/ceph storage · redhat/openshift container storage · redhat/openshift data foundation · redhat/enterprise linux · fedoraproject/fedora
- Source
- secalert@redhat.com
References
- https://github.com/JuliaLang/julia/issues/42415Issue Tracking, Patch, Third Party Advisory
- https://github.com/Reference-LAPACK/lapack/commit/38f3eeee3108b18158409ca2a100e6fe03754781Patch, Third Party Advisory
- https://github.com/Reference-LAPACK/lapack/pull/625Issue Tracking, Patch, Third Party Advisory
- https://github.com/xianyi/OpenBLAS/commit/2be5ee3cca97a597f2ee2118808a2d5eacea050cPatch, Third Party Advisory
- https://github.com/xianyi/OpenBLAS/commit/337b65133df174796794871b3988cd03426e6d41Patch, Third Party Advisory
- https://github.com/xianyi/OpenBLAS/commit/ddb0ff5353637bb5f5ad060c9620e334c143e3d7Patch, Third Party Advisory
- https://github.com/xianyi/OpenBLAS/commit/fe497efa0510466fd93578aaf9da1ad8ed4edbe7Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QFEVOCUG2UXMVMFMTU4ONJVDEHY2LW2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DROZM4M2QRKSD6FBO4BHSV2QMIRJQPHT/
- https://github.com/JuliaLang/julia/issues/42415Issue Tracking, Patch, Third Party Advisory
- https://github.com/Reference-LAPACK/lapack/commit/38f3eeee3108b18158409ca2a100e6fe03754781Patch, Third Party Advisory
- https://github.com/Reference-LAPACK/lapack/pull/625Issue Tracking, Patch, Third Party Advisory
- https://github.com/xianyi/OpenBLAS/commit/2be5ee3cca97a597f2ee2118808a2d5eacea050cPatch, Third Party Advisory
- https://github.com/xianyi/OpenBLAS/commit/337b65133df174796794871b3988cd03426e6d41Patch, Third Party Advisory
- https://github.com/xianyi/OpenBLAS/commit/ddb0ff5353637bb5f5ad060c9620e334c143e3d7Patch, Third Party Advisory
- https://github.com/xianyi/OpenBLAS/commit/fe497efa0510466fd93578aaf9da1ad8ed4edbe7Patch, Third Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6QFEVOCUG2UXMVMFMTU4ONJVDEHY2LW2/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DROZM4M2QRKSD6FBO4BHSV2QMIRJQPHT/
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.