Out-of-bounds read in lapack - CVE-2021-4048
Published: November 14, 2022
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack. A remote attacker can pass specially crafted data to the application, trigger an out-of-bounds read error and crash the affected application.
Affected software
Oracle Business Intelligence Enterprise Edition
Oracle Linux
SUSE Manager Server
SUSE Manager Proxy
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise High Performance Computing
openEuler
Fedora
Juniper Secure Analytics (JSA)
openblas
openblas-devel
openblas-debuginfo
openblas-debugsource
openblas (Red Hat package)
blas-devel
liblapack3-debuginfo
liblapack3
libblas3-debuginfo
libblas3
liblapacke3-debuginfo
liblapacke3
lapacke-devel-static
lapacke-devel
lapack-devel-static
lapack-devel
lapack-debugsource
blas-devel-static
lapack
lapack-help
QRadar User Behavior Analytics
OpenShift Data Foundation (formerly OpenShift Container Storage)
How to mitigate CVE-2021-4048
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
openblas - update to 0.3.10-3
openblas-devel - update to 0.3.10-3
openblas-debuginfo - update to 0.3.10-3
openblas-debugsource - update to 0.3.10-3
openblas (Red Hat package) - update to 0.3.15-4.el8
blas-devel - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
liblapack3-debuginfo - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
liblapack3 - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
libblas3-debuginfo - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
libblas3 - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
liblapacke3-debuginfo - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
liblapacke3 - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
lapacke-devel-static - update to 3.5.0-3.9.1
lapacke-devel - update to 3.5.0-3.9.1
lapack-devel-static - update to 3.5.0-3.9.1
lapack-devel - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
lapack-debugsource - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
blas-devel-static - update to 3.5.0-3.9.1
lapack - addressed in versions 3.9.0-5, 3.9.0-6
lapack-help - addressed in versions 3.9.0-5, 3.9.0-6
lapack-devel - addressed in versions 3.9.0-5, 3.9.0-6
lapack - addressed in versions 3.9.0-7.fc34, 3.10.0-4.fc35
QRadar User Behavior Analytics - update to 4.1.14
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0
External References
- https://github.com/JuliaLang/julia/issues/42415
- https://github.com/xianyi/OpenBLAS/commit/337b65133df174796794871b3988cd03426e6d41
- https://github.com/xianyi/OpenBLAS/commit/2be5ee3cca97a597f2ee2118808a2d5eacea050c
- https://github.com/xianyi/OpenBLAS/commit/ddb0ff5353637bb5f5ad060c9620e334c143e3d7
- https://github.com/Reference-LAPACK/lapack/commit/38f3eeee3108b18158409ca2a100e6fe03754781
- https://github.com/Reference-LAPACK/lapack/pull/625
- https://github.com/xianyi/OpenBLAS/commit/fe497efa0510466fd93578aaf9da1ad8ed4edbe7
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/6QFEVOCUG2UXMVMFMTU4ONJVDEHY2LW2/
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/DROZM4M2QRKSD6FBO4BHSV2QMIRJQPHT/
Related Security Bulletins
- Denial of service in lapack
- Red Hat Enterprise Linux 8 update for openblas
- SUSE update for lapack
- SUSE update for lapack
- Multiple vulnerabilities in Oracle Business Intelligence Enterprise Edition
- Multiple vulnerabilities in Oracle Linux
- Multiple vulnerabilities in Red Hat OpenShift Data Foundation 4.14
- Multiple vulnerabilities in IBM QRadar User Behavior Analytics
- Juniper Networks Juniper Secure Analytics update for third-party applications
- openEuler update for lapack
- openEuler update for openblas
- openEuler 20.03 LTS SP3 update for lapack
- Fedora 34 update for lapack
- Fedora 35 update for lapack