Out-of-bounds Read
CVE-2021-4048
Summary
An out-of-bounds read flaw was found in the "CLARRV", "DLARRV", "SLARRV", and "ZLARRV" functions in LAPACK version through 3.10.0, as also used in OpenBLAS version through 0.3.17. Specially crafted inputs passed to these functions could cause an application using LAPACK to crash or possibly disclose portions of its memory.
- LOW
- NETWORK
- NONE
- UNCHANGED
- NONE
- NONE
- HIGH
- HIGH
CWE-125 - Out-of-Bounds Read
Out-of-bounds read is a vulnerability that allows access to memory beyond the authorized accessible location. Such a vulnerability compromises the confidentiality of the trusted environment in the application and enables an attacker to launch further attacks by leveraging the exposed information.
References
Advisory Timeline
- Published