9.1
CVSSv3

CVE-2021-4048

Published: 08/12/2021 Updated: 07/11/2023
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P

Vulnerability Summary

An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

lapack project lapack

openblas project openblas

julialang julia 1.7.0

julialang julia

redhat ceph storage 3.0

redhat ceph storage 2.0

redhat enterprise linux 8.0

redhat ceph storage 4.0

redhat ceph storage 5.0

redhat openshift container storage 4.0

redhat openshift data foundation 4.0

fedoraproject fedora 34

fedoraproject fedora 35

Vendor Advisories

Debian Bug report logs - #1001902 lapack: CVE-2021-4048 Package: src:lapack; Maintainer for src:lapack is Debian Science Team <debian-science-maintainers@listsaliothdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sat, 18 Dec 2021 17:03:02 UTC Severity: important Tags: security, upstream Fo ...
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack and OpenBLAS A specially crafted input passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory (CVE-2021-4048) ...
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack and OpenBLAS A specially crafted input passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory (CVE-2021-4048) ...
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack and OpenBLAS A specially crafted input passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory (CVE-2021-4048) ...