Bug 2024358 (CVE-2021-4048) - CVE-2021-4048 lapack: Out-of-bounds read in *larrv
Summary: CVE-2021-4048 lapack: Out-of-bounds read in *larrv
Alias: CVE-2021-4048
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
Depends On: Red Hat2024361 Red Hat2024362 Red Hat2024364 Red Hat2024365 Red Hat2029857 Red Hat2030822 Red Hat2093179 Red Hat2024363 Red Hat2024366 2029851 Red Hat2029854 Red Hat2029855 Red Hat2029856 Red Hat2030823
Blocks: Embargoed2024359 Red Hat2030461
TreeView+ depends on / blocked
Reported: 2021-11-17 22:46 UTC by Sage McTaggart
Modified: 2022-12-03 20:16 UTC (History)
27 users (show)

Fixed In Version: openblas 0.3.18
Doc Type: If docs needed, set a value
Doc Text:
An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack and OpenBLAS. A specially crafted input passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.
Clone Of:
Last Closed: 2022-12-03 20:16:44 UTC

Attachments (Terms of Use)

System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2022:7639 0 None None None 2022-11-08 09:59:21 UTC

Description Sage McTaggart 2021-11-17 22:46:21 UTC
OpenBLAS contains an out-of-bounds read error in the zlarrv.f library that occurs when user input is not validated properly. This could allow a remote attacker to crash the process associated with the library, or potentially expose the contents of memory by executing arbitrary code.



Comment 3 Tomas Hoger 2021-11-19 12:33:18 UTC
There's only limited amount of information currently included in this report.  Using what's available - file name zlarrv.f and information that the issue should be fixed in openblas 0.3.18 led me to this openblas upstream commit:


This fix is for the lapack library bundled in openblas, and references the following lapack upstream issue and commit:


which points to the original report:


When porting the fix from lapack to openblas, the patch was split to 4 separate commits.  In addition to the one listed above for zlarrv.f, other commits are:


Comment 4 Tomas Hoger 2021-11-30 21:47:22 UTC
There is no released fixed lapack version yet - the current release is 3.10.0 that was released before this fix was made.

Comment 5 Tomas Hoger 2021-11-30 22:09:21 UTC
The lapack and openblas packages included in Red Hat Enterprise Linux are not widely used by other packages in the distribution.  There's no package requiring lapack in Red Hat Enterprise Linux 8.  The openblas package in Red Hat Enterprise Linux 8 is only directly required by opencv (which is used by frei0r-plugins and hence gnome-video-effects) and Python numpy and scipy modules (which use openblas in their numpy.linalg and scipy.linalg submodules).

Comment 6 Tomas Hoger 2021-12-07 13:15:58 UTC
Making this public.  Fixes in lapack and openblas have been public since end of Sep / early Oct.  Only the VulnDB entry is not publicly visible, but will likely remain restricted to customers of the service.

Comment 7 Tomas Hoger 2021-12-07 13:16:15 UTC
Created lapack tracking bugs for this issue:

Affects: fedora-all [bug 2029851]

Comment 12 errata-xmlrpc 2022-11-08 09:59:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2022:7639 https://access.redhat.com/errata/RHSA-2022:7639

Comment 13 Product Security DevOps Team 2022-12-03 20:16:41 UTC
This bug is now closed. Further updates for individual products will be reflected on the CVE page(s):


Note You need to log in before you can comment on or make changes to this bug.