{"id":"CVE-2021-3520","title":"There's a flaw in lz4","summary":"There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/o…","severity":"critical","cvss":9.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-190","CWE-190","CWE-787"],"vendor":"lz4_project","product":"lz4","affected":["lz4 >= 1.8.3, < 1.9.4","active_iq_unified_manager","cloud_backup","ontap_select_deploy_administration_utility","communications_cloud_native_core_policy = 1.14.0","zfs_storage_appliance_kit = 8.8","universal_forwarder >= 8.2.0, < 8.2.12","universal_forwarder >= 9.0.0, < 9.0.6","universal_forwarder = 9.1.0"],"patched":["lz4 1.9.4","universal_forwarder 9.0.6"],"published":"2021-06-02","updated":"2026-10-08","sourceUpdated":"2026-10-08T21:17:40.463","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2021-3520","references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1954559","label":"secalert@redhat.com"},{"url":"https://security.netapp.com/advisory/ntap-20211104-0005/","label":"secalert@redhat.com"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"secalert@redhat.com"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"secalert@redhat.com"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"secalert@redhat.com"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1954559","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://security.netapp.com/advisory/ntap-20211104-0005/","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com//security-alerts/cpujul2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuapr2022.html","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://www.oracle.com/security-alerts/cpuoct2021.html","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd"],"epss":0.03216,"epssPercentile":0.87824,"ingestedAt":"2026-10-08T22:11:53.733Z","slug":"CVE-2021-3520","body":"## Overview\n\nThere's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.\n\n## Affected\n\n- `lz4 >= 1.8.3, < 1.9.4`\n- `active_iq_unified_manager`\n- `cloud_backup`\n- `ontap_select_deploy_administration_utility`\n- `communications_cloud_native_core_policy = 1.14.0`\n- `zfs_storage_appliance_kit = 8.8`\n- `universal_forwarder >= 8.2.0, < 8.2.12`\n- `universal_forwarder >= 9.0.0, < 9.0.6`\n- `universal_forwarder = 9.1.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `lz4 1.9.4`\n- `universal_forwarder 9.0.6`","depth":"midnight","depthScore":55,"depthScoreParts":{"impact":53.9,"likelihood":0.6,"exploitation":0,"ransomware":0},"changes":[]}