VDB

GCVE-VVD-MAGEIA-2021-229

GCVE-VVD-MAGEIA-2021-229
Advisory Published
Vulnetix · Advisory published December 5, 2021
An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well (CVE-2021-3520).

Affected Products

VendorProductVersionsPlatforms
Mageiabtrfs-progs0 (affected), 5.15.1-1.mga8 (unaffected)
Mageiaethtool0 (affected), 5.15-1.mga8 (unaffected)
Mageiaiproute20 (affected), 5.15.0-1.mga8 (unaffected)
Mageiaipset0 (affected), 7.15-1.mga8 (unaffected)
Mageiaipt_NETFLOW0 (affected), 2.6-1.mga8 (unaffected)
Mageiaiw0 (affected), 5.16-1.mga8 (unaffected)
Mageialibseccomp0 (affected), 2.5.3-1.mga8 (unaffected)
Mageiastrace0 (affected), 5.15-1.mga8 (unaffected)
Mageiaxfsprogs0 (affected), 5.14.1-1.mga8 (unaffected)
Mageialz40 (affected), 1.9.2-1.1.mga7 (unaffected), 0 (affected), 1.9.2-1.1.mga7 (unaffected)
Mageialz40 (affected), 1.9.3-1.1.mga8 (unaffected), 0 (affected), 1.9.3-1.1.mga8 (unaffected)

References

Browse GCVE Records

100 records in the GCVE database · Updated April 16, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›