yocto ▾
›
kirkstone ▾
›
vulnerability
›
CVE-2021-43612
Component Overview
Vulnerability Overview
Name
CVE-2021-43612
Source
NVD (
link
)
Debian (
link
)
Description
In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets.
CWEs
CWE-787
CWE-787
Published Date
Apr 15, 2023
Updated Date
Jun 17, 2026
Workaround
-
Advisories
https://github.com/lldpd/lldpd/commit/73d42680fce8598324364dbb31b9bc3b8320adf7
Patch
https://github.com/lldpd/lldpd/compare/1.0.12...1.0.13
Patch
https://lldpd.github.io/security.html
Patch
https://github.com/lldpd/lldpd/commit/73d42680fce8598324364dbb31b9bc3b8320adf7
Patch
https://github.com/lldpd/lldpd/compare/1.0.12...1.0.13
Patch
https://lldpd.github.io/security.html
Patch
Analysis
#
Affected Component
Analysis
lldpd
Exploitable
Vulnerability Ratings
#
7.5
CVSSv31
7.5
CVSSv31
NaN
other
Others affected components
#
Name
Project
Project Version
Version
Status
lldpd
buildroot
2025.02.x
1.0.18
Not Affected
lldpd
buildroot
master
1.0.20
Not Affected
lldpd
openwrt
master
1.0.22-r1
Not Affected
lldpd
openwrt
openwrt-25.12
1.0.20-r1
Not Affected
lldpd
yocto
master
1.0.22
Not Affected
lldpd
yocto
scarthgap
1.0.18
Not Affected