openSUSE-SU-2026:21146-1

See a problem?
Import Source
https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21146-1.json
JSON Data
https://api.osv.dev/v1/vulns/openSUSE-SU-2026:21146-1
Upstream
Related
Published
2026-06-22T13:05:26Z
Modified
2026-06-30T18:24:45Z
Summary
Security update for lldpd
Details

This update for lldpd fixes the following issues:

Changes in lldpd:

  • Update to version 1.0.22

    • Fix CVE-2026-46433, out-of-bound read access when removing VLAN tag (#787).
    • Reject 0-length management address in LLDP.
    • Fix race condition when creating the control socket.
    • Fix FDP MAC address.
    • Fix memory leak in the BSD bridge query path.
    • Fix duplicate management addresses when merging EDP VLAN frames.
  • Update to version 1.0.21 Changes:

    • Add "configure lldp portdescription-source" to choose how to populate port description. Fix:
    • Fix path traversal vulnerabilities in the privileged process.
    • Fix arbitrary file deletion in the privileged process.
    • Fix accuracy of Dot3 MAU types advertised and add support for 200G and 400G.
    • Fix detection of wireless interfaces.
  • Update to version 1.0.20 Changes:

    • Enable fast start unconditionally (and move its configuration in "configure lldp").
    • Make VLAN advertisements configurable. Fix:
    • Do not break zero-copy traffic on Linux.
    • Fix crash on rapid addition/removal of interfaces.
    • Fix management address selection when pattern is a negative IP address.
  • Update to version 1.0.19 Changes:

    • Add cvlan/svlan/tpmr capabilities.
    • Add lldpctl_watch_sync_unblock to liblldpctl.
    • Add C++ wrapper for lldpctl. Fix:
    • Fix AppArmor policy for /run/lldpd/lldpd.socket.lock.
    • Do not query stats for a down interface on Linux.
References

Affected packages

openSUSE:Leap 16.0 / lldpd

Package

Name
lldpd
Purl
pkg:rpm/opensuse/lldpd&distro=openSUSE%20Leap%2016.0

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.0.22-bp160.1.1

Ecosystem specific

{
    "binaries":  [
        {
            "liblldpctl4":  "1.0.22-bp160.1.1",
            "lldpd":  "1.0.22-bp160.1.1",
            "lldpd-devel":  "1.0.22-bp160.1.1"
        }
    ]
}

Database specific

source
"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21146-1.json"