CVE-2021-4048

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
08/12/2021
Last modified:
07/11/2023

Description

An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lapack_project:lapack:*:*:*:*:*:*:*:* 3.10.0 (including)
cpe:2.3:a:openblas_project:openblas:*:*:*:*:*:*:*:* 0.3.18 (excluding)
cpe:2.3:a:julialang:julia:*:*:*:*:*:*:*:* 1.6.3 (including)
cpe:2.3:a:julialang:julia:1.7.0:beta1:*:*:*:*:*:*
cpe:2.3:a:julialang:julia:1.7.0:beta2:*:*:*:*:*:*
cpe:2.3:a:julialang:julia:1.7.0:beta3:*:*:*:*:*:*
cpe:2.3:a:julialang:julia:1.7.0:beta4:*:*:*:*:*:*
cpe:2.3:a:julialang:julia:1.7.0:rc1:*:*:*:*:*:*
cpe:2.3:a:redhat:ceph_storage:2.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ceph_storage:3.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ceph_storage:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:ceph_storage:5.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_container_storage:4.0:*:*:*:*:*:*:*
cpe:2.3:a:redhat:openshift_data_foundation:4.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:8.0:*:*:*:*:*:*:*