Memory leak in lldpd - CVE-2020-27827
Published: January 21, 2021
Vulnerability identifier: #VU49910
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-27827
CWE-ID: CWE-401
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform DoS attack on the target system.
The vulnerability exists due memory leak in lldpd when processing packets with multiple instances of certain TLVs. A remote attacker can send specially crafted traffic to the system and perform a denial of service (DoS) attack.
Affected software
lldpd
Arch Linux
Gentoo Linux
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
openEuler
Fedora
lldpd (Alpine package)
openvswitch (Red Hat package)
openvswitch (Alpine package)
openvswitch (Debian package)
ovn2.11 (Red Hat package)
openvswitch2.11 (Red Hat package)
openvswitch2.13 (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
lldpd
lldpd (Red Hat package)
lldpd-devel
openvswitch-common (Ubuntu package)
openvswitch-debugsource
openvswitch
openvswitch-help
openvswitch-devel
openvswitch-debuginfo
net-misc/openvswitch
dpdk
Open vSwitch
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat Enterprise Linux Fast Datapath
Red Hat OpenShift Container Platform
Arch Linux
Gentoo Linux
Anolis OS
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Ubuntu
openEuler
Fedora
lldpd (Alpine package)
openvswitch (Red Hat package)
openvswitch (Alpine package)
openvswitch (Debian package)
ovn2.11 (Red Hat package)
openvswitch2.11 (Red Hat package)
openvswitch2.13 (Red Hat package)
redhat-release-virtualization-host (Red Hat package)
redhat-virtualization-host (Red Hat package)
lldpd
lldpd (Red Hat package)
lldpd-devel
openvswitch-common (Ubuntu package)
openvswitch-debugsource
openvswitch
openvswitch-help
openvswitch-devel
openvswitch-debuginfo
net-misc/openvswitch
dpdk
Open vSwitch
Red Hat Virtualization
Red Hat Virtualization for IBM Power LE
Red Hat Enterprise Linux Fast Datapath
Red Hat OpenShift Container Platform
How to mitigate CVE-2020-27827
Install updates from vendor's website.
lldpd - update to 1.0.8
lldpd (Alpine package) - update to 1.0.8-r0
Open vSwitch - addressed in versions 2.6.9, 2.7.12, 2.8.10, 2.9.8, 2.10.6, 2.11.5, 2.12.2, 2.13.2, 2.14.1
openvswitch (Red Hat package) - update to 2.9.9-1.el7fdp
openvswitch (Alpine package) - update to 2.12.2-r0
openvswitch (Debian package) - update to 2.10.6+ds1-0+deb10u
ovn2.11 (Red Hat package) - update to 2.11.1-57.el7fdp
openvswitch2.11 (Red Hat package) - addressed in versions 2.11.3-83.el8fdp, 2.11.3-86.el7fdp
openvswitch2.13 (Red Hat package) - addressed in versions 2.13.0-79.5.el8fdp, 2.13.0-81.el7fdp
redhat-release-virtualization-host (Red Hat package) - update to 4.3.14-2.el7ev
redhat-virtualization-host (Red Hat package) - update to 4.3.14-20210322.0.el7_9
lldpd - addressed in versions 1.0.16-1.fc36, 1.0.16-1.fc37, 1.0.16-1.fc38
lldpd (Red Hat package) - update to 1.0.18-4.el9
lldpd - update to 1.0.18-4.0.1
lldpd-devel - update to 1.0.18-4.0.1
openvswitch-common (Ubuntu package) - addressed in versions 2.5.9-0ubuntu0.16.04.2, 2.9.7-0ubuntu0.18.04.2, 2.13.1-0ubuntu0.20.04.3, 2.13.1-0ubuntu1.2
openvswitch-debugsource - update to 2.12.0-11
openvswitch - update to 2.12.0-11
openvswitch-help - update to 2.12.0-11
openvswitch-devel - update to 2.12.0-11
openvswitch-debuginfo - update to 2.12.0-11
openvswitch - update to 2.15.0-1.fc33
net-misc/openvswitch - update to 2.17.6
Red Hat OpenShift Container Platform - update to 4.7.4
dpdk - update to 20.11-1.fc33
lldpd (Alpine package) - update to 1.0.8-r0
Open vSwitch - addressed in versions 2.6.9, 2.7.12, 2.8.10, 2.9.8, 2.10.6, 2.11.5, 2.12.2, 2.13.2, 2.14.1
openvswitch (Red Hat package) - update to 2.9.9-1.el7fdp
openvswitch (Alpine package) - update to 2.12.2-r0
openvswitch (Debian package) - update to 2.10.6+ds1-0+deb10u
ovn2.11 (Red Hat package) - update to 2.11.1-57.el7fdp
openvswitch2.11 (Red Hat package) - addressed in versions 2.11.3-83.el8fdp, 2.11.3-86.el7fdp
openvswitch2.13 (Red Hat package) - addressed in versions 2.13.0-79.5.el8fdp, 2.13.0-81.el7fdp
redhat-release-virtualization-host (Red Hat package) - update to 4.3.14-2.el7ev
redhat-virtualization-host (Red Hat package) - update to 4.3.14-20210322.0.el7_9
lldpd - addressed in versions 1.0.16-1.fc36, 1.0.16-1.fc37, 1.0.16-1.fc38
lldpd (Red Hat package) - update to 1.0.18-4.el9
lldpd - update to 1.0.18-4.0.1
lldpd-devel - update to 1.0.18-4.0.1
openvswitch-common (Ubuntu package) - addressed in versions 2.5.9-0ubuntu0.16.04.2, 2.9.7-0ubuntu0.18.04.2, 2.13.1-0ubuntu0.20.04.3, 2.13.1-0ubuntu1.2
openvswitch-debugsource - update to 2.12.0-11
openvswitch - update to 2.12.0-11
openvswitch-help - update to 2.12.0-11
openvswitch-devel - update to 2.12.0-11
openvswitch-debuginfo - update to 2.12.0-11
openvswitch - update to 2.15.0-1.fc33
net-misc/openvswitch - update to 2.17.6
Red Hat OpenShift Container Platform - update to 4.7.4
dpdk - update to 20.11-1.fc33
External References
Related Security Bulletins
- Memory leak in lldpd
- Arch Linux update for lldpd
- Arch Linux update for openvswitch
- Memory leak in lldp in Open vSwitch
- Debian update for openvswitch
- Memory leak in lldpd (Alpine package)
- Memory leak in openvswitch (Alpine package)
- Red Hat Enterprise Linux 8 update for openvswitch2.13
- Red Hat Enterprise Linux Fast Datapath 7 update for openvswitch2.11
- Red Hat Enterprise Linux Fast Datapath update for openvswitch2.13
- Red Hat Enterprise Linux Fast Datapath 8 update for openvswitch2.11
- Multiple vulnerabilities in Red Hat Virtualization
- Denial of service in Red Hat Virtualization
- Red Hat Enterprise Linux Fast Datapath update for openvswitch
- Red Hat OpenStack Platform 13.0 update for openvswitch2.11
- Ubuntu update for openvswitch
- Fedora 36 update for lldpd
- Fedora 37 update for lldpd
- Fedora 38 update for lldpd
- Gentoo update for Open vSwitch
- openEuler 20.03 LTS SP1 update for openvswitch
- Red Hat Enterprise Linux 9 update for lldpd
- Multiple vulnerabilities in Red Hat OpenShift Container Platform 4.7
- Fedora 33 update for dpdk, openvswitch
- Anolis OS update for lldpd