vulnerability

Oracle Linux: CVE-2021-43612: ELSA-2024-9158: lldpd security update (MODERATE)

Severity
7
CVSS
(AV:A/AC:L/Au:S/C:C/I:N/A:C)
Published
Nov 18, 2021
Added
Nov 21, 2024
Modified
Dec 3, 2025

Description

In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
An out-of-bounds read vulnerability is present in lldpd. An attacker on the same network as the vulnerable system may use this vulnerability to leak memory data from the application or crash it by sending shorter SONMP packets than what is expected.

Solutions

oracle-linux-upgrade-lldpdoracle-linux-upgrade-lldpd-devel
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.