Integer overflow in LZ4 - CVE-2021-3520
Published: May 24, 2021 / Updated: March 31, 2023
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to integer overflow in the fast LZ compression algorithm library. A remote attacker can pass specially crafted archive, trick the victim into opening it, trigger integer overflow and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Arch Linux
Amazon Linux AMI
Gentoo Linux
SUSE Manager Proxy
SUSE Manager Retail Branch Server
SUSE Manager Server
SUSE CaaS Platform
SUSE MicroOS
SUSE Enterprise Storage
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Anolis OS
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux Server - TUS
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat Enterprise Linux for x86_64 - Extended Update Support
SUSE Linux Enterprise Software Development Kit
Ubuntu
SUSE Linux Enterprise Server for SAP
SUSE Linux Enterprise High Performance Computing
SUSE Linux Enterprise Server
SUSE Linux Enterprise Module for Basesystem
openEuler
API Portal
AMQ Streams
cflinuxfs3
librdkafka
Red Hat Integration Camel Extensions for Quarkus
Service Telemetry Framework
Red Hat Integration Camel-K
Migration Toolkit for Containers
Cloud Pak for Security (CP4S)
lz4 (Debian package)
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
Red Hat Enterprise Linux Server for x86_64 - Update Services for SAP Solutions
liblz4-1 (Ubuntu package)
liblz4-1
liblz4-1-debuginfo
lz4-debuginfo
lz4-debugsource
liblz4-1-32bit-debuginfo
liblz4-1-32bit
lz4
liblz4-devel
lz4-devel
lz4-libs
lz4 (Red Hat package)
lz4-help
app-arch/lz4
Oracle Communications Cloud Native Core Policy
Red Hat OpenShift Jaeger
Splunk Universal Forwarder
Splunk Enterprise
IBM Security Verify Access
HPE NonStop Virtual Tape Repository (VTR)
Dell EMC Unity Operating Environment (OE)
Dell EMC Unity XT Operating Environment (OE)
Dell EMC Unity VSA Operating Environment (OE)
Web Terminal
OpenShift Virtualization
How to mitigate CVE-2021-3520
API Portal - update to February 2022
cflinuxfs3 - update to 0.240.0
librdkafka - update to 2.1.0
Migration Toolkit for Containers - addressed in versions 1.4.6, 1.5.1
Cloud Pak for Security (CP4S) - update to 1.8.0.0
lz4 (Debian package) - update to 1.8.3-1+deb10u1
Red Hat OpenShift Jaeger - addressed in versions 1.20.5, 1.24.0
Splunk Universal Forwarder - addressed in versions 8.1.14, 8.2.11, 9.0.5
Splunk Enterprise - addressed in versions 8.2.12, 9.0.6, 9.1.1
HPE NonStop Virtual Tape Repository (VTR) - update to T09644V01^AAK
liblz4-1 (Ubuntu package) - addressed in versions 0.0~r131-2ubuntu3.1, 0.0~r1312ubuntu2+esm1, 1.9.2-2ubuntu0.20.04.1, 1.9.2-2ubuntu0.20.10.1, 1.9.3-1ubuntu0.1
Web Terminal - update to 1.3
Red Hat Integration Camel-K - update to 1.8
liblz4-1 - addressed in versions 1.8.0-3.3.1, 1.8.0-3.8.1, 1.9.2-3.3.1
liblz4-1-debuginfo - addressed in versions 1.8.0-3.3.1, 1.8.0-3.8.1, 1.9.2-3.3.1
lz4-debuginfo - addressed in versions 1.8.0-3.3.1, 1.8.0-3.8.1, 1.9.2-3.3.1
lz4-debugsource - addressed in versions 1.8.0-3.3.1, 1.8.0-3.8.1, 1.9.2-3.3.1
liblz4-1-32bit-debuginfo - addressed in versions 1.8.0-3.8.1, 1.9.2-3.3.1
liblz4-1-32bit - addressed in versions 1.8.0-3.8.1, 1.9.2-3.3.1
lz4 - addressed in versions 1.8.0-3.8.1, 1.9.2-3.3.1
liblz4-devel - addressed in versions 1.8.0-3.8.1, 1.9.2-3.3.1
lz4 - update to 1.8.3-3
lz4-devel - update to 1.8.3-3
lz4-libs - update to 1.8.3-3
lz4 (Red Hat package) - update to 1.8.3-3.el8_4
lz4-help - update to 1.9.2-3
lz4-debugsource - update to 1.9.2-3
lz4-debuginfo - update to 1.9.2-3
lz4-devel - update to 1.9.2-3
lz4 - update to 1.9.2-3
app-arch/lz4 - update to 1.9.3-r1
lz4 - update to 1.9.4-1
AMQ Streams - addressed in versions 2.1.0, 2.7.0
OpenShift Virtualization - addressed in versions 2.6.6, 4.8.0, 4.8.1
Dell EMC Unity Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity XT Operating Environment (OE) - update to 5.1.2.0.5.007
Dell EMC Unity VSA Operating Environment (OE) - update to 5.1.2.0.5.007
External References
Related Security Bulletins
- Remote code execution in LZ4
- Arch Linux update for lz4
- Debian update for lz4
- Remote code execution in Cloud Foundry Foundation cflinuxfs3
- Red Hat Enterprise Linux 8.4 update for lz4
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers
- Multiple vulnerabilities in Red Hat OpenShift Jaeger
- Multiple vulnerabilities in Red Hat Migration Toolkit for Containers
- Multiple vulnerabilities in Red Hat Web Terminal
- Multiple vulnerabilities in Dell EMC Unity
- Multiple vulnerabilities in IBM Security Verify Access
- Multiple vulnerabilities in Oracle Communications Cloud Native Core Policy
- SUSE update for lz4
- SUSE update for lz4
- SUSE update for lz4
- Ubuntu update for lz4
- Ubuntu update for lz4
- Multiple vulnerabilities in Red Hat Integration Camel Extensions for Quarkus 2.7
- Multiple vulnerabilities in Red Hat Service Telemetry Framework
- Multiple vulnerabilities in IBM Cloud Pak for Security
- Multiple vulnerabilities in Red Hat Integration Camel-K
- Multiple vulnerabilities in API Portal
- Multiple vulnerabilities in librdkafka
- Splunk Universal Forwarder update for third-party packages
- Splunk Enterprise update for third-party packages
- openEuler 20.03 LTS SP1 update for lz4
- Multiple vulnerabilities in AMQ Streams 2.7
- Gentoo update for LZ4
- Amazon Linux AMI update for lz4
- Multiple vulnerabilities in HPE NonStop Vrtual Tape Repository (VTR)
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in OpenShift Virtualization 2.6
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Multiple vulnerabilities in AMQ Streams 2.1
- Anolis OS update for lz4