CVE-2021-43612

NameCVE-2021-43612
DescriptionIn lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3389-1, ELA-829-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lldpd (PTS)jessie0.7.11-2+deb8u1vulnerable
stretch (lts), stretch0.9.6-1+deb9u2fixed
buster1.0.3-1vulnerable
buster (security)1.0.3-1+deb10u2fixed
bullseye (security), bullseye1.0.11-1+deb11u2fixed
bookworm (security), bookworm1.0.16-1+deb12u1fixed
sid, trixie1.0.18-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lldpdsourcestretch0.9.6-1+deb9u1ELA-829-1
lldpdsourcebuster1.0.3-1+deb10u1DLA-3389-1
lldpdsourcebullseye1.0.11-1+deb11u1
lldpdsource(unstable)1.0.13-1

Notes

[stretch] - lldpd <no-dsa> (Minor issue)
https://github.com/lldpd/lldpd/commit/73d42680fce8598324364dbb31b9bc3b8320adf7 (1.0.13)
[jessie] - lldpd <no-dsa> (Minor issue)

Search for package or bug name: Reporting problems