9.1

CVE-2021-4048

An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.

Data is provided by the National Vulnerability Database (NVD)
Lapack ProjectLapack Version <= 3.10.0
Openblas ProjectOpenblas Version < 0.3.18
JulialangJulia Version <= 1.6.3
JulialangJulia Version1.7.0 Updatebeta1
JulialangJulia Version1.7.0 Updatebeta2
JulialangJulia Version1.7.0 Updatebeta3
JulialangJulia Version1.7.0 Updatebeta4
JulialangJulia Version1.7.0 Updaterc1
RedhatCeph Storage Version2.0
RedhatCeph Storage Version3.0
RedhatCeph Storage Version4.0
RedhatCeph Storage Version5.0
RedhatEnterprise Linux Version8.0
FedoraprojectFedora Version34
FedoraprojectFedora Version35
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.37% 0.577
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
nvd@nist.gov 6.4 10 4.9
AV:N/AC:L/Au:N/C:P/I:N/A:P
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.