CVE-2021-43612

NameCVE-2021-43612
DescriptionIn lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-3389-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
lldpd (PTS)buster1.0.3-1vulnerable
buster (security)1.0.3-1+deb10u2fixed
bullseye (security), bullseye1.0.11-1+deb11u2fixed
bookworm, bookworm (security)1.0.16-1+deb12u1fixed
sid, trixie1.0.18-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
lldpdsourcebuster1.0.3-1+deb10u1DLA-3389-1
lldpdsourcebullseye1.0.11-1+deb11u1
lldpdsource(unstable)1.0.13-1

Notes

[stretch] - lldpd <no-dsa> (Minor issue)
https://github.com/lldpd/lldpd/commit/73d42680fce8598324364dbb31b9bc3b8320adf7 (1.0.13)

Search for package or bug name: Reporting problems