Alerts This Week
Warning Icon 1 1,213
Alerts This Week
Warning Icon 1 1,213

openSUSE Leap 16.0 lldpd Moderate Out-Of-Bound Read CVE-2026-46433

opensuse
Calendar Grey June 30, 2026
Dist Opensuse Esm H88
An update resolves a moderate vulnerability in openSUSE lldpd with instructions for installation and package details.
An update that solves one vulnerability can now be installed.

Description

This update for lldpd fixes the following issues:

Changes in lldpd:

- Update to version 1.0.22

* Fix CVE-2026-46433, out-of-bound read access when removing

VLAN tag (#787).

* Reject 0-length management address in LLDP.

* Fix race condition when creating the control socket.

* Fix FDP MAC address.

* Fix memory leak in the BSD bridge query path.

* Fix duplicate management addresses when merging EDP VLAN

frames.

- Update to version 1.0.21

Changes:

* Add "configure lldp portdescription-source" to choose how to

populate port description.

Fix:

* Fix path traversal vulnerabilities in the privileged process.

* Fix arbitrary file deletion in the privileged process.

* Fix accuracy of Dot3 MAU types advertised and add support for

200G and 400G.

* Fix detection of wireless interfaces.

- Update to version 1.0.20

Changes:

* Enable fast start unconditionally (and move its configuration

in "configure lldp").

* Make VLAN advertisements...

Read the Full Advisory

Patch

Package List

- openSUSE Leap 16.0:

liblldpctl4-1.0.22-bp160.1.1

lldpd-1.0.22-bp160.1.1

lldpd-devel-1.0.22-bp160.1.1

References

* https://www.suse.com/security/cve/CVE-2026-46433.html

Severity
moderate
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2026:21146-1
Rating: moderate
Affected Products: openSUSE Leap 16.0 -------------------------------------------------------------

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here