---
id: CVE-2021-3520
title: There's a flaw in lz4
summary: >-
  There's a flaw in lz4. An attacker who submits a crafted file to an
  application linked with lz4 may be able to trigger an integer overflow,
  leading to calling of memmove() on a negative size argument, causing an
  out-of-bounds write and/o…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-190
  - CWE-190
  - CWE-787
vendor: lz4_project
product: lz4
affected:
  - 'lz4 >= 1.8.3, < 1.9.4'
  - active_iq_unified_manager
  - cloud_backup
  - ontap_select_deploy_administration_utility
  - communications_cloud_native_core_policy = 1.14.0
  - zfs_storage_appliance_kit = 8.8
  - 'universal_forwarder >= 8.2.0, < 8.2.12'
  - 'universal_forwarder >= 9.0.0, < 9.0.6'
  - universal_forwarder = 9.1.0
patched:
  - lz4 1.9.4
  - universal_forwarder 9.0.6
published: '2021-06-02'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T21:17:40.463'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-3520'
references:
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1954559'
    label: secalert@redhat.com
  - url: 'https://security.netapp.com/advisory/ntap-20211104-0005/'
    label: secalert@redhat.com
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: secalert@redhat.com
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: secalert@redhat.com
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: secalert@redhat.com
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=1954559'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20211104-0005/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com//security-alerts/cpujul2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuapr2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpuoct2021.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
epss: 0.03216
epssPercentile: 0.87824
ingestedAt: '2026-10-08T22:11:53.733Z'
---

## Overview

There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.

## Affected

- `lz4 >= 1.8.3, < 1.9.4`
- `active_iq_unified_manager`
- `cloud_backup`
- `ontap_select_deploy_administration_utility`
- `communications_cloud_native_core_policy = 1.14.0`
- `zfs_storage_appliance_kit = 8.8`
- `universal_forwarder >= 8.2.0, < 8.2.12`
- `universal_forwarder >= 9.0.0, < 9.0.6`
- `universal_forwarder = 9.1.0`

## Remediation

Upgrade past the affected range:

- `lz4 1.9.4`
- `universal_forwarder 9.0.6`
