Integer overflow in LZ4 - CVE-2021-3520

 

Integer overflow in LZ4 - CVE-2021-3520

Published: May 24, 2021 / Updated: March 31, 2023


Vulnerability identifier: #VU53439
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-3520
CWE-ID: CWE-190
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to integer overflow in the fast LZ compression algorithm library. A remote attacker can pass specially crafted archive, trick the victim into opening it, trigger integer overflow and execute arbitrary code on the target system.

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.


Affected software

LZ4
Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
openEuler
API Portal
AMQ Streams
cflinuxfs3
librdkafka
Red Hat Integration Camel Extensions for Quarkus
Service Telemetry Framework
Red Hat Integration Camel-K
Migration Toolkit for Containers
Cloud Pak for Security (CP4S)
lz4 (Debian package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
liblz4-1 (Ubuntu package)
liblz4-1
liblz4-1-debuginfo
lz4-debuginfo
lz4-debugsource
liblz4-1-32bit-debuginfo
liblz4-1-32bit
lz4
liblz4-devel
lz4-devel
lz4-libs
lz4 (Red Hat package)
lz4-help
app-arch/lz4
Oracle Communications Cloud Native Core Policy
Red Hat OpenShift Jaeger
Splunk Universal Forwarder
Splunk Enterprise
IBM Security Verify Access
HPE NonStop Virtual Tape Repository (VTR)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Web Terminal
OpenShift Virtualization

How to mitigate CVE-2021-3520

Install update from vendor's website.

LZ4 - update to 1.9.4
API Portal - update to February 2022
cflinuxfs3 - update to 0.240.0
librdkafka - update to 2.1.0
Migration Toolkit for Containers - addressed in versions 1.4.6, 1.5.1
Cloud Pak for Security (CP4S) - update to 1.8.0.0
lz4 (Debian package) - update to 1.8.3-1+deb10u1
Red Hat OpenShift Jaeger - addressed in versions 1.20.5, 1.24.0
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
HPE NonStop Virtual Tape Repository (VTR) - update to T09644V01^AAK
liblz4-1 (Ubuntu package) - addressed in versions 0.0~r131-2ubuntu3.1, 0.0~r1312ubuntu2+esm1, 1.9.2-2ubuntu0.20.04.1, 1.9.2-2ubuntu0.20.10.1, 1.9.3-1ubuntu0.1
Web Terminal - update to 1.3
Red Hat Integration Camel-K - update to 1.8
liblz4-1 - addressed in versions 1.8.0-3.3.1, 1.8.0-3.8.1, 1.9.2-3.3.1
liblz4-1-debuginfo - addressed in versions 1.8.0-3.3.1, 1.8.0-3.8.1, 1.9.2-3.3.1
lz4-debuginfo - addressed in versions 1.8.0-3.3.1, 1.8.0-3.8.1, 1.9.2-3.3.1
lz4-debugsource - addressed in versions 1.8.0-3.3.1, 1.8.0-3.8.1, 1.9.2-3.3.1
liblz4-1-32bit-debuginfo - addressed in versions 1.8.0-3.8.1, 1.9.2-3.3.1
liblz4-1-32bit - addressed in versions 1.8.0-3.8.1, 1.9.2-3.3.1
lz4 - addressed in versions 1.8.0-3.8.1, 1.9.2-3.3.1
liblz4-devel - addressed in versions 1.8.0-3.8.1, 1.9.2-3.3.1
lz4 - update to 1.8.3-3
lz4-devel - update to 1.8.3-3
lz4-libs - update to 1.8.3-3
lz4 (Red Hat package) - update to 1.8.3-3.el8_4
lz4-help - update to 1.9.2-3
lz4-debugsource - update to 1.9.2-3
lz4-debuginfo - update to 1.9.2-3
lz4-devel - update to 1.9.2-3
lz4 - update to 1.9.2-3
app-arch/lz4 - update to 1.9.3-r1
lz4 - update to 1.9.4-1
AMQ Streams - addressed in versions 2.1.0, 2.7.0
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0, 4.8.1
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007

External References

Related Security Bulletins