VDB
GCVE-VVD-MAGEIA-2021-229
GCVE-VVD-MAGEIA-2021-229
Advisory Published
An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well (CVE-2021-3520).
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | btrfs-progs | 0 (affected), 5.15.1-1.mga8 (unaffected) | — |
| Mageia | ethtool | 0 (affected), 5.15-1.mga8 (unaffected) | — |
| Mageia | iproute2 | 0 (affected), 5.15.0-1.mga8 (unaffected) | — |
| Mageia | ipset | 0 (affected), 7.15-1.mga8 (unaffected) | — |
| Mageia | ipt_NETFLOW | 0 (affected), 2.6-1.mga8 (unaffected) | — |
| Mageia | iw | 0 (affected), 5.16-1.mga8 (unaffected) | — |
| Mageia | libseccomp | 0 (affected), 2.5.3-1.mga8 (unaffected) | — |
| Mageia | strace | 0 (affected), 5.15-1.mga8 (unaffected) | — |
| Mageia | xfsprogs | 0 (affected), 5.14.1-1.mga8 (unaffected) | — |
| Mageia | lz4 | 0 (affected), 1.9.2-1.1.mga7 (unaffected), 0 (affected), 1.9.2-1.1.mga7 (unaffected) | — |
| Mageia | lz4 | 0 (affected), 1.9.3-1.1.mga8 (unaffected), 0 (affected), 1.9.3-1.1.mga8 (unaffected) | — |
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.