system/lz4: CVE-2021-3520 was not fixed in the last bump
Commit 7a1df7bb indicates that CVE-2021-3520 was fixed.
But the 1.9.3
release was made in 2020, while the CVE was reported in 2021.
Commit 7a1df7bb indicates that CVE-2021-3520 was fixed.
But the 1.9.3
release was made in 2020, while the CVE was reported in 2021.
mentioned in commit 9443af51
mentioned in commit 6cb1f3ee
mentioned in commit d505b70a
closed with commit d505b70a