Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
An update that solves one vulnerability can now be installed.. openSUSE security update: security update for lldpd ------------------------------------------------------------- Announcement ID: openSUSE-SU-2026:21146-1 Rating: moderate Cross-References: * CVE-2026-46433 Affected Products: openSUSE Leap 16.0 ------------------------------------------------------------- An update that solves one vulnerability can now be installed. Description: This update for lldpd fixes the following issues: Changes in lldpd: - Update to version 1.0.22 * Fix CVE-2026-46433, out-of-bound read access when removing VLAN tag (#787). * Reject 0-length management address in LLDP. * Fix race condition when creating the control socket. * Fix FDP MAC address. * Fix memory leak in the BSD bridge query path. * Fix duplicate management addresses when merging EDP VLAN frames. - Update to version 1.0.21 Changes: * Add "configure lldp portdescription-source" to choose how to populate port description. Fix: * Fix path traversal vulnerabilities in the privileged process. * Fix arbitrary file deletion in the privileged process. * Fix accuracy of Dot3 MAU types advertised and add support for 200G and 400G. * Fix detection of wireless interfaces. - Update to version 1.0.20 Changes: * Enable fast start unconditionally (and move its configuration in "configure lldp"). * Make VLAN advertisements configurable. Fix: * Do not break zero-copy traffic on Linux. * Fix crash on rapid addition/removal of interfaces. * Fix management address selection when pattern is a negative IP address. - Update to version 1.0.19 Changes: * Add cvlan/svlan/tpmr capabilities. * Add lldpctl_watch_sync_unblock to liblldpctl. * Add C++ wrapper for lldpctl. Fix: * Fix AppArmor policy for /run/lldpd/lldpd.socket.lock. * Do not query stats for a down interface on Linux. Patch instructions: To install this openSUSE security update use the suse recommended installationmethods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 16.0 zypper in -t patch openSUSE-Leap-16.0-packagehub-341=1 Package List: - openSUSE Leap 16.0: liblldpctl4-1.0.22-bp160.1.1 lldpd-1.0.22-bp160.1.1 lldpd-devel-1.0.22-bp160.1.1 References: * https://www.suse.com/security/cve/CVE-2026-46433.html . An update resolves a moderate vulnerability in openSUSE lldpd with instructions for installation and package details.. openSUSE security update,lldpd moderate patch,installed vulnerability fix. . Severity: moderate. LinuxSecurity.com Team
Matteo Memelli reported an out-of-bounds read flaw when parsing CDP addresses in lldpd, an implementation of the IEEE 802.1ab (LLDP) protocol. A remote attacker can take advantage of this flaw to cause a denial of service via a specially crafted CDP PDU packet. . - ------------------------------------------------------------------------- Debian Security Advisory DSA-5505-1
Matteo Memelli discovered a flaw in lldpd, an implementation of the IEEE 802.1ab protocol. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. . ------------------------------------------------------------------------- Debian LTS Advisory DLA-3578-1
Update to the latest 1.0.16: * Lots of updates, enhancements and fixes from 1.0.4 * CVEs: CVE-2020-27827, CVE-2021-43612. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-3e4feeadec 2023-04-20 05:23:47.393434 --------------------------------------------------------------------------------Name : lldpd Product : Fedora 36 Version : 1.0.16 Release : 1.fc36 URL : https://github.com/lldpd/ Summary : ISC-licensed implementation of LLDP Description : LLDP is an industry standard protocol designed to supplant proprietary Link-Layer protocols such as EDP or CDP. The goal of LLDP is to provide an inter-vendor compatible mechanism to deliver Link-Layer notifications to adjacent network devices. --------------------------------------------------------------------------------Update Information: Update to the latest 1.0.16: * Lots of updates, enhancements and fixes from 1.0.4 * CVEs: CVE-2020-27827, CVE-2021-43612 --------------------------------------------------------------------------------ChangeLog: * Tue Apr 11 2023 Peter Robinson - 1.0.16-1 - Update to 1.0.16 - Modernise spec file - CVEs: CVE-2020-27827, CVE-2020-27827, CVE-2021-43612 * Thu Jan 19 2023 Fedora Release Engineering - 1.0.4-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Thu Dec 8 2022 Florian Weimer - 1.0.4-11 - Port configure script to C99 * Thu Jul 21 2022 Fedora Release Engineering - 1.0.4-10 - Rebuilt for https://fedoraproject.org/wiki/Fedora_37_Mass_Rebuild --------------------------------------------------------------------------------References: [ 1 ] Bug #1797336 - lldpd-1.0.16 is available https://bugzilla.redhat.com/show_bug.cgi?id=1797336 [ 2 ] Bug #1921441 - CVE-2020-27827 lldpd: lldp/openvswitch: denial of service via externally triggered memory leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1921441 [ 3 ] Bug #2040390 -CVE-2021-43612 lldpd: heap-based buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2040390 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-3e4feeadec' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to the latest 1.0.16: * Lots of updates, enhancements and fixes from 1.0.4 * CVEs: CVE-2020-27827, CVE-2021-43612. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-c0c184a019 2023-04-20 02:53:04.598559 --------------------------------------------------------------------------------Name : lldpd Product : Fedora 37 Version : 1.0.16 Release : 1.fc37 URL : https://github.com/lldpd/ Summary : ISC-licensed implementation of LLDP Description : LLDP is an industry standard protocol designed to supplant proprietary Link-Layer protocols such as EDP or CDP. The goal of LLDP is to provide an inter-vendor compatible mechanism to deliver Link-Layer notifications to adjacent network devices. --------------------------------------------------------------------------------Update Information: Update to the latest 1.0.16: * Lots of updates, enhancements and fixes from 1.0.4 * CVEs: CVE-2020-27827, CVE-2021-43612 --------------------------------------------------------------------------------ChangeLog: * Tue Apr 11 2023 Peter Robinson - 1.0.16-1 - Update to 1.0.16 - Modernise spec file - CVEs: CVE-2020-27827, CVE-2020-27827, CVE-2021-43612 * Thu Jan 19 2023 Fedora Release Engineering - 1.0.4-12 - Rebuilt for https://fedoraproject.org/wiki/Fedora_38_Mass_Rebuild * Thu Dec 8 2022 Florian Weimer - 1.0.4-11 - Port configure script to C99 --------------------------------------------------------------------------------References: [ 1 ] Bug #1797336 - lldpd-1.0.16 is available https://bugzilla.redhat.com/show_bug.cgi?id=1797336 [ 2 ] Bug #1921441 - CVE-2020-27827 lldpd: lldp/openvswitch: denial of service via externally triggered memory leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1921441 [ 3 ] Bug #2040390 - CVE-2021-43612 lldpd: heap-based buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2040390 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-c0c184a019' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Update to the latest 1.0.16: * Lots of updates, enhancements and fixes from 1.0.4 * CVEs: CVE-2020-27827, CVE-2021-43612. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2023-88991d2713 2023-04-19 01:38:17.099647 --------------------------------------------------------------------------------Name : lldpd Product : Fedora 38 Version : 1.0.16 Release : 1.fc38 URL : https://github.com/lldpd/ Summary : ISC-licensed implementation of LLDP Description : LLDP is an industry standard protocol designed to supplant proprietary Link-Layer protocols such as EDP or CDP. The goal of LLDP is to provide an inter-vendor compatible mechanism to deliver Link-Layer notifications to adjacent network devices. --------------------------------------------------------------------------------Update Information: Update to the latest 1.0.16: * Lots of updates, enhancements and fixes from 1.0.4 * CVEs: CVE-2020-27827, CVE-2021-43612 --------------------------------------------------------------------------------ChangeLog: * Tue Apr 11 2023 Peter Robinson - 1.0.16-1 - Update to 1.0.16 - Modernise spec file - CVEs: CVE-2020-27827, CVE-2020-27827, CVE-2021-43612 --------------------------------------------------------------------------------References: [ 1 ] Bug #1797336 - lldpd-1.0.16 is available https://bugzilla.redhat.com/show_bug.cgi?id=1797336 [ 2 ] Bug #1921441 - CVE-2020-27827 lldpd: lldp/openvswitch: denial of service via externally triggered memory leak [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=1921441 [ 3 ] Bug #2040390 - CVE-2021-43612 lldpd: heap-based buffer overflow [fedora-all] https://bugzilla.redhat.com/show_bug.cgi?id=2040390 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2023-88991d2713' at the command line.For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
* The following was previously incorrectly announced to this list * * as DLA-3388-1. The correct DLA identifier for this advisory is * * DLA-3389-1. * . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3389-1
It was discovered that there were two potential denial of service (DoS) attacks in lldpd, a implementation of the IEEE 802.1ab (LLDP) protocol used to administer and monitor networking devices. . - ------------------------------------------------------------------------- Debian LTS Advisory DLA-3388-1
Get the latest Linux and open source security news straight to your inbox.