RUSTSEC-2022-0051

    Dashboard / Vulnerabilities / RUSTSEC-2022-0051

    RUSTSEC-2022-0051

    Published: 25 Aug 2022Last Modified: 4 Feb 2026
    Aliases:

    Summary: Memory corruption in liblz4

    Details: lz4-sys up to v1.9.3 bundles a version of liblz4 that is vulnerable to [CVE-2021-3520](https://nvd.nist.gov/vuln/detail/CVE-2021-3520). Attackers could craft a payload that triggers an integer overflow upon decompression, causing an out-of-bounds write. The flaw has been corrected in version v1.9.4 of liblz4, which is included in lz4-sys 1.9.4.

    Affected packages

    Package

    Name: lz4-sys

    Purl: pkg:cargo/lz4-sys

    Affected ranges

    Type: SEMVER

    Events:

    Introduced- 0.0.0-0
    Fixed -1.9.4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    RUSTSEC-2022-0051 | CVE-DB