OESA-2021-1478

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1478
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1478.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2021-1478
Upstream
Published
2021-12-31T11:03:26Z
Modified
2025-09-03T06:17:37.896558Z
Summary
openblas security update
Details

An optimized BLAS library based on GotoBLAS2 1.13 BSD version.

Security Fix(es):

An out-of-bounds read flaw was found in the CLARRV, DLARRV, SLARRV, and ZLARRV functions in lapack through version 3.10.0, as also used in OpenBLAS before version 0.3.18. Specially crafted inputs passed to these functions could cause an application using lapack to crash or possibly disclose portions of its memory.(CVE-2021-4048)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / openblas

Package

Name
openblas
Purl
pkg:rpm/openEuler/openblas&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.10-3.oe1

Ecosystem specific

{
    "src": [
        "openblas-0.3.10-3.oe1.src.rpm"
    ],
    "x86_64": [
        "openblas-debuginfo-0.3.10-3.oe1.x86_64.rpm",
        "openblas-devel-0.3.10-3.oe1.x86_64.rpm",
        "openblas-0.3.10-3.oe1.x86_64.rpm",
        "openblas-debugsource-0.3.10-3.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "openblas-devel-0.3.10-3.oe1.aarch64.rpm",
        "openblas-debuginfo-0.3.10-3.oe1.aarch64.rpm",
        "openblas-0.3.10-3.oe1.aarch64.rpm",
        "openblas-debugsource-0.3.10-3.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP2 / openblas

Package

Name
openblas
Purl
pkg:rpm/openEuler/openblas&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
0.3.10-3.oe1

Ecosystem specific

{
    "src": [
        "openblas-0.3.10-3.oe1.src.rpm"
    ],
    "x86_64": [
        "openblas-devel-0.3.10-3.oe1.x86_64.rpm",
        "openblas-debuginfo-0.3.10-3.oe1.x86_64.rpm",
        "openblas-0.3.10-3.oe1.x86_64.rpm",
        "openblas-debugsource-0.3.10-3.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "openblas-debuginfo-0.3.10-3.oe1.aarch64.rpm",
        "openblas-debugsource-0.3.10-3.oe1.aarch64.rpm",
        "openblas-devel-0.3.10-3.oe1.aarch64.rpm",
        "openblas-0.3.10-3.oe1.aarch64.rpm"
    ]
}