$OpenBSD: patch-lib_lz4_c,v 1.3 2021/05/21 17:06:23 tj Exp $

CVE-2021-3520 

Index: lib/lz4.c
--- lib/lz4.c.orig
+++ lib/lz4.c
@@ -1749,7 +1749,7 @@ LZ4_decompress_generic(
                  const size_t dictSize         /* note : = 0 if noDict */
                  )
 {
-    if (src == NULL) { return -1; }
+    if ((src == NULL) || (outputSize < 0)) { return -1; }
 
     {   const BYTE* ip = (const BYTE*) src;
         const BYTE* const iend = ip + srcSize;
