In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
CVSS Details
- CVSS 3.1 Base Score: 7.5
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade lldpd-develUpgrade lldpd | Nov 19, 2024 | Apr 15, 2023 |
| Alpine Linux | — | Upgrade lldpd | Aug 22, 2024 | Apr 15, 2023 |
| Debian | — | Upgrade lldpd | Apr 13, 2023 | Apr 13, 2023 |
| Oracle_linux | — | Upgrade lldpd-develUpgrade lldpd | Nov 21, 2024 | Nov 18, 2021 |
| Redhat_linux | — | No solution existsUpgrade lldpd-debuginfoUpgrade lldpd-develUpgrade lldpd-debugsourceUpgrade lldpd | Nov 13, 2024 | Apr 15, 2023 |
| Rocky_linux | — | Upgrade lldpd-debuginfoUpgrade lldpd-debugsourceUpgrade lldpd-develUpgrade lldpd | Mar 18, 2025 | Apr 15, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub