{"id":"CVE-2021-20285","details":"A flaw was found in upx canPack in p_lx_elf.cpp in UPX 3.96. This flaw allows attackers to cause a denial of service (SEGV or buffer overflow and application crash) or possibly have unspecified other impacts via a crafted ELF. The highest threat from this vulnerability is to system availability.","modified":"2026-07-09T00:22:17.747505Z","published":"2021-03-26T17:15:13.140Z","related":["openSUSE-SU-2023:0088-1"],"references":[{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1937787"},{"type":"REPORT","url":"https://github.com/upx/upx/issues/421"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/upx/upx","events":[{"introduced":"d7ba31cab8ce8d95d2c10e88d2ec787ac52005ef"},{"last_affected":"d7ba31cab8ce8d95d2c10e88d2ec787ac52005ef"}],"database_specific":{"cpe":"cpe:2.3:a:upx:upx:3.96:*:*:*:*:*:*:*","extracted_events":[{"introduced":"3.96"},{"last_affected":"3.96"}],"source":"CPE_STRING"}}],"versions":["3.96","v3.96"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2021-20285.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H"}]}