CVE-2023-41910

NameCVE-2023-41910
DescriptionAn issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3578-1, DSA-5505-1, ELA-958-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lldpd (PTS)jessie0.7.11-2+deb8u1vulnerable
stretch (lts), stretch0.9.6-1+deb9u2fixed
buster1.0.3-1vulnerable
buster (security)1.0.3-1+deb10u2fixed
bullseye (security), bullseye1.0.11-1+deb11u2fixed
bookworm (security), bookworm1.0.16-1+deb12u1fixed
sid, trixie1.0.18-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lldpdsourcejessie(unfixed)end-of-life
lldpdsourcestretch0.9.6-1+deb9u2ELA-958-1
lldpdsourcebuster1.0.3-1+deb10u2DLA-3578-1
lldpdsourcebullseye1.0.11-1+deb11u2DSA-5505-1
lldpdsourcebookworm1.0.16-1+deb12u1DSA-5505-1
lldpdsource(unstable)1.0.17-1

Notes

Fixed by: https://github.com/lldpd/lldpd/commit/a9aeabdf879c25c584852a0bb5523837632f099b (1.0.17)

Search for package or bug name: Reporting problems