[Debian]: CVE: CVE-2021-43612: lldpd an out-of-bounds heap read via short SONMP packets

Bug #2018641 reported by Yue Tao
256
This bug affects 1 person
Affects Status Importance Assigned to Milestone
StarlingX
Fix Released
High
Zhixiong Chi

Bug Description

CVE-2021-43612: https://nvd.nist.gov/vuln/detail/CVE-2021-43612

In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.

Score:
cve_id status cvss3Score
CVE-2021-43612 fixed 7.5

References:

lldpd_1.0.11-1+deb11u1

CVE References

Yue Tao (wrytao)
tags: added: stx.9.0 stx.security
Changed in starlingx:
importance: Undecided → High
status: New → Triaged
Changed in starlingx:
assignee: nobody → Zhixiong Chi (zhixiongchi)
status: Triaged → In Progress
Revision history for this message
OpenStack Infra (hudson-openstack) wrote : Fix merged to integ (master)

Reviewed: https://review.opendev.org/c/starlingx/integ/+/882797
Committed: https://opendev.org/starlingx/integ/commit/d1f4e2645d88046f703fc1c8876035b9512f829c
Submitter: "Zuul (22348)"
Branch: master

commit d1f4e2645d88046f703fc1c8876035b9512f829c
Author: Zhixiong Chi <email address hidden>
Date: Tue May 9 10:32:55 2023 +0800

    lldpd: Upgrade lldpd to 1.0.11-1+deb11u1

    Fix CVE-2021-43612

    Refer to:
    https://security-tracker.debian.org/tracker/CVE-2021-43612

    TestPlan:
    PASS: downloader
    PASS: build-pkgs -a -c
    PASS: build-image
    PASS: Jenkins Installation.
    PASS: dpkg -l |grep lldpd
    ii lldpd 1.0.11-1+deb11u1.stx.4

    Closes-Bug: 2018641

    Signed-off-by: Zhixiong Chi <email address hidden>
    Change-Id: I33215c6cca7ef4839e4555f709b4824595a82ee2

Changed in starlingx:
status: In Progress → Fix Released
To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.