Skip to main content

Out-of-bounds Read

CVE-2021-4048

Severity High
Score 9.1/10

Summary

An out-of-bounds read flaw was found in the "CLARRV", "DLARRV", "SLARRV", and "ZLARRV" functions in LAPACK version through 3.10.0, as also used in OpenBLAS version through 0.3.17. Specially crafted inputs passed to these functions could cause an application using LAPACK to crash or possibly disclose portions of its memory.

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • HIGH
  • HIGH

CWE-125 - Out-of-Bounds Read

Out-of-bounds read is a vulnerability that allows access to memory beyond the authorized accessible location. Such a vulnerability compromises the confidentiality of the trusted environment in the application and enables an attacker to launch further attacks by leveraging the exposed information.

Advisory Timeline

  • Published