vulnerability
Oracle Linux: CVE-2021-43612: ELSA-2024-9158: lldpd security update (MODERATE)
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 7 | (AV:A/AC:L/Au:S/C:C/I:N/A:C) | Nov 18, 2021 | Nov 21, 2024 | Dec 3, 2025 |
Severity
7
CVSS
(AV:A/AC:L/Au:S/C:C/I:N/A:C)
Published
Nov 18, 2021
Added
Nov 21, 2024
Modified
Dec 3, 2025
Description
In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
An out-of-bounds read vulnerability is present in lldpd. An attacker on the same network as the vulnerable system may use this vulnerability to leak memory data from the application or crash it by sending shorter SONMP packets than what is expected.
An out-of-bounds read vulnerability is present in lldpd. An attacker on the same network as the vulnerable system may use this vulnerability to leak memory data from the application or crash it by sending shorter SONMP packets than what is expected.
Solutions
oracle-linux-upgrade-lldpdoracle-linux-upgrade-lldpd-devel
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.