Debian Security Advisory

DSA-5505-1 lldpd -- security update

Date Reported:
25 Sep 2023
Affected Packages:
lldpd
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2023-41910.
More information:

Matteo Memelli reported an out-of-bounds read flaw when parsing CDP addresses in lldpd, an implementation of the IEEE 802.1ab (LLDP) protocol. A remote attacker can take advantage of this flaw to cause a denial of service via a specially crafted CDP PDU packet.

For the oldstable distribution (bullseye), this problem has been fixed in version 1.0.11-1+deb11u2.

For the stable distribution (bookworm), this problem has been fixed in version 1.0.16-1+deb12u1.

We recommend that you upgrade your lldpd packages.

For the detailed security status of lldpd please refer to its security tracker page at: \https://security-tracker.debian.org/tracker/lldpd