Out-of-bounds read in lapack - CVE-2021-4048

 

Out-of-bounds read in lapack - CVE-2021-4048

Published: November 14, 2022


Vulnerability identifier: #VU69295
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-4048
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a boundary condition within the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack. A remote attacker can pass specially crafted data to the application, trigger an out-of-bounds read error and crash the affected application.


Affected software

lapack
Oracle Business Intelligence Enterprise Edition
Oracle Linux
SUSE Manager Server
SUSE Manager Proxy
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat CodeReady Linux Builder for x86_64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
SUSE Linux Enterprise Software Development Kit
SUSE Linux Enterprise Server for SAP Applications
SUSE Linux Enterprise Server
SUSE Linux Enterprise Realtime Extension
SUSE Linux Enterprise Desktop
SUSE Linux Enterprise Module for Basesystem
SUSE Linux Enterprise Module for Development Tools
SUSE Linux Enterprise High Performance Computing
openEuler
Fedora
Juniper Secure Analytics (JSA)
openblas
openblas-devel
openblas-debuginfo
openblas-debugsource
openblas (Red Hat package)
blas-devel
liblapack3-debuginfo
liblapack3
libblas3-debuginfo
libblas3
liblapacke3-debuginfo
liblapacke3
lapacke-devel-static
lapacke-devel
lapack-devel-static
lapack-devel
lapack-debugsource
blas-devel-static
lapack
lapack-help
QRadar User Behavior Analytics
OpenShift Data Foundation (formerly OpenShift Container Storage)

How to mitigate CVE-2021-4048

Install update from vendor's website.

lapack - update to 3.10.0
Juniper Secure Analytics (JSA) - update to 7.5.0 UP7 IF04
openblas - update to 0.3.10-3
openblas-devel - update to 0.3.10-3
openblas-debuginfo - update to 0.3.10-3
openblas-debugsource - update to 0.3.10-3
openblas (Red Hat package) - update to 0.3.15-4.el8
blas-devel - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
liblapack3-debuginfo - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
liblapack3 - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
libblas3-debuginfo - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
libblas3 - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
liblapacke3-debuginfo - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
liblapacke3 - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
lapacke-devel-static - update to 3.5.0-3.9.1
lapacke-devel - update to 3.5.0-3.9.1
lapack-devel-static - update to 3.5.0-3.9.1
lapack-devel - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
lapack-debugsource - addressed in versions 3.5.0-3.9.1, 3.5.0-4.6.1
blas-devel-static - update to 3.5.0-3.9.1
lapack - addressed in versions 3.9.0-5, 3.9.0-6
lapack-help - addressed in versions 3.9.0-5, 3.9.0-6
lapack-devel - addressed in versions 3.9.0-5, 3.9.0-6
lapack - addressed in versions 3.9.0-7.fc34, 3.10.0-4.fc35
QRadar User Behavior Analytics - update to 4.1.14
OpenShift Data Foundation (formerly OpenShift Container Storage) - update to 4.14.0

External References

Related Security Bulletins