Buffer overflow in lldpd - CVE-2015-8011
Published: January 28, 2020 / Updated: December 4, 2020
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to a boundary error within the lldp_decode() function in daemon/protocols/lldp.c in lldpd. A remote attacker can pass specially crafted data to the application, trigger memory corruption and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.
Affected software
Arch Linux
Ubuntu
openEuler
Fedora
cockpit-ovirt (Red Hat package)
v2v-conversion-host (Red Hat package)
openvswitch (Red Hat package)
openvswitch (Debian package)
openvswitch2.11 (Red Hat package)
ovn2.11 (Red Hat package)
openvswitch (Alpine package)
openvswitch2.13 (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
openshift-clients (Red Hat package)
openvswitch-common (Ubuntu package)
openvswitch-debuginfo
openvswitch
openvswitch-help
openvswitch-devel
openvswitch-debugsource
python-sushy (Red Hat package)
rhvm-appliance (Red Hat package)
dpdk
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
OpenShift Virtualization
Red Hat Virtualization Host
Red Hat Virtualization Manager
Red Hat OpenShift Container Platform
Red Hat Enterprise Linux Fast Datapath
Red Hat OpenStack
How to mitigate CVE-2015-8011
cockpit-ovirt (Red Hat package) - update to 0.14.15-1.el8ev
v2v-conversion-host (Red Hat package) - update to 1.16.2-8.el8ev
openvswitch (Red Hat package) - update to 2.9.9-1.el7fdp
openvswitch (Debian package) - update to 2.10.6+ds1-0+deb10u
openvswitch2.11 (Red Hat package) - addressed in versions 2.11.3-74.el8fdp, 2.11.3-77.el7fdp
ovn2.11 (Red Hat package) - update to 2.11.1-56.el7fdp
openvswitch (Alpine package) - update to 2.12.2-r0
openvswitch2.13 (Red Hat package) - addressed in versions 2.13.0-62.el7fdp, 2.13.0-71.el8fdp, 2.13.0-72.el8fdp
redhat-release-virtualization-host (Red Hat package) - addressed in versions 4.3.12-4.el7ev, 4.4.3-2.el8ev
redhat-virtualization-host (Red Hat package) - addressed in versions 4.3.12-20201216.0.el7_9, 4.4.3-20201210.0.el8_3
Red Hat OpenShift Container Platform - addressed in versions 4.5.23, 4.6.8, 4.6.9
openshift-clients (Red Hat package) - addressed in versions 4.6.0-202012121455.p0.git.3800.80a13a6.el7, 4.6.0-202012121455.p0.git.3800.80a13a6.el8
openvswitch-common (Ubuntu package) - addressed in versions 2.5.9-0ubuntu0.16.04.2, 2.9.7-0ubuntu0.18.04.2, 2.13.1-0ubuntu0.20.04.3, 2.13.1-0ubuntu1.2
openvswitch-debuginfo - update to 2.12.0-11
openvswitch - update to 2.12.0-11
openvswitch-help - update to 2.12.0-11
openvswitch-devel - update to 2.12.0-11
openvswitch-debugsource - update to 2.12.0-11
openvswitch - update to 2.15.0-1.fc33
python-sushy (Red Hat package) - update to 3.5.0-2.20201005161238.74b8111.el8
rhvm-appliance (Red Hat package) - update to 4.4-20210310.0.el8ev
OpenShift Virtualization - update to 4.8.1
dpdk - update to 20.11-1.fc33
External References
Related Security Bulletins
- Multiple vulnerabilities in lldpd
- Red Hat Enterprise Linux Fast Datapath 7 update for openvswitch2.13
- Red Hat Enterprise Linux Fast Datapath 7 update for openvswitch2.11
- Red Hat Enterprise Linux Fast Datapath 8 update for openvswitch2.13
- Red Hat Enterprise Linux Fast Datapath 8 update for openvswitch2.11
- Multiple vulnerabilities in OpenShift Container Platform
- Multiple vulnerabilities in Red Hat OpenShift Container Platform
- Red Hat update for Red Hat Virtualization
- OpenShift Container Platform update for lldpd vulnerability
- Red Hat Virtualization update for lldpd
- Arch Linux update for openvswitch
- Debian update for openvswitch
- Buffer overflow in openvswitch (Alpine package)
- Red Hat Enterprise Linux Fast Datapath update for openvswitch
- Red Hat OpenStack Platform 10 update for openvswitch
- Ubuntu update for openvswitch
- Red Hat Virtualization 4 for Red Hat Enterprise Linux 8 update for rhvm-appliance
- openEuler 20.03 LTS SP1 update for openvswitch
- Multiple vulnerabilities in OpenShift Virtualization 4.8
- Fedora 33 update for dpdk, openvswitch