VDB
RHSA-2022%3A1345
RHSA-2022%3A1345
PUBLISHED
CVSS 8.600000381469727 HIGH
There's a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
Risk Scores
CVSS 3.1
8.600000381469727
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat AMQ Streams 2.1.0 |
Timeline
- Apr 13, 2022 CVE Published
- May 1, 2026 Distribution Patch
- May 1, 2026 Distribution Patch
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 1, 2026 Security Advisory
- May 14, 2026 CVE Updated
References
- https://access.redhat.com/errata/RHSA-2022:1345 advisory
- https://access.redhat.com/security/updates/classification/#moderate advisory
- https://access.redhat.com/jbossnetwork/restricted/listSoftware.html?downloadType=distributions&product=jboss.amq.streams&version=2.1.0 advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1954559 issue
- https://bugzilla.redhat.com/show_bug.cgi?id=2031958 issue
- https://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_1345.json advisory
- https://access.redhat.com/security/cve/CVE-2021-3520 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-3520 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-3520 advisory
- https://access.redhat.com/security/cve/CVE-2021-43797 advisory
- https://www.cve.org/CVERecord?id=CVE-2021-43797 advisory
- https://nvd.nist.gov/vuln/detail/CVE-2021-43797 advisory
- https://github.com/netty/netty/security/advisories/GHSA-wx5j-54mm-rqqq advisory