Theres a flaw in lz4. An attacker who submits a crafted file to an application linked with lz4 may be able to trigger an integer overflow, leading to calling of memmove() on a negative size argument, causing an out-of-bounds write and/or a crash. The greatest impact of this flaw is to availability, with some potential impact to confidentiality and integrity as well.
The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Lz4 | Lz4_project | 1.8.3 (including) | 1.9.4 (excluding) |
Red Hat AMQ Streams 2.1.0 | RedHat | lz4 | * |
Red Hat AMQ Streams 2.7.0 | RedHat | * | |
Red Hat Enterprise Linux 8 | RedHat | lz4-0:1.8.3-3.el8_4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-controller-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-log-reader-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-must-gather-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-operator-bundle:v1.4.6-5 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-registry-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-rsync-transfer-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-ui-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-velero-plugin-for-aws-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-velero-plugin-for-gcp-rhel8:v1.4.6-3 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-velero-plugin-for-microsoft-azure-rhel8:v1.4.6-4 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-velero-restic-restore-helper-rhel8:v1.4.6-5 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-migration-velero-rhel8:v1.4.6-5 | * |
Red Hat Migration Toolkit for Containers 1.4 | RedHat | rhmtc/openshift-velero-plugin-rhel8:v1.4.6-4 | * |
RHAF Camel-K 1.8 | RedHat | lz4 | * |
RHINT Camel-Q 2.7 | RedHat | lz4 | * |
Lz4 | Ubuntu | bionic | * |
Lz4 | Ubuntu | esm-infra-legacy/trusty | * |
Lz4 | Ubuntu | esm-infra/bionic | * |
Lz4 | Ubuntu | esm-infra/focal | * |
Lz4 | Ubuntu | esm-infra/xenial | * |
Lz4 | Ubuntu | focal | * |
Lz4 | Ubuntu | groovy | * |
Lz4 | Ubuntu | hirsute | * |
Lz4 | Ubuntu | trusty | * |
Lz4 | Ubuntu | trusty/esm | * |
Lz4 | Ubuntu | upstream | * |
Lz4 | Ubuntu | xenial | * |