Vulnerability Description
In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lldpd Project | Lldpd | < 1.0.13 |
| Fedoraproject | Fedora | 36 |
Related Weaknesses (CWE)
References
- https://github.com/lldpd/lldpd/commit/73d42680fce8598324364dbb31b9bc3b8320adf7Patch
- https://github.com/lldpd/lldpd/compare/1.0.12...1.0.13PatchRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lldpd.github.io/security.htmlPatchThird Party Advisory
- https://github.com/lldpd/lldpd/commit/73d42680fce8598324364dbb31b9bc3b8320adf7Patch
- https://github.com/lldpd/lldpd/compare/1.0.12...1.0.13PatchRelease Notes
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedorapro
- https://lldpd.github.io/security.htmlPatchThird Party Advisory
FAQ
What is CVE-2021-43612?
CVE-2021-43612 is a vulnerability with a CVSS score of 7.5 (HIGH). In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
How severe is CVE-2021-43612?
CVE-2021-43612 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43612?
Check the references section above for vendor advisories and patch information. Affected products include: Lldpd Project Lldpd, Fedoraproject Fedora.