{"id":"openSUSE-SU-2026:21146-1","summary":"Security update for lldpd","details":"This update for lldpd fixes the following issues:\n\nChanges in lldpd:\n\n- Update to version 1.0.22\n  * Fix CVE-2026-46433, out-of-bound read access when removing\n    VLAN tag (#787).\n  * Reject 0-length management address in LLDP.\n  * Fix race condition when creating the control socket.\n  * Fix FDP MAC address.\n  * Fix memory leak in the BSD bridge query path.\n  * Fix duplicate management addresses when merging EDP VLAN\n    frames.\n\n- Update to version 1.0.21\n  Changes:\n  * Add \"configure lldp portdescription-source\" to choose how to\n    populate port description.\n  Fix:\n  * Fix path traversal vulnerabilities in the privileged process.\n  * Fix arbitrary file deletion in the privileged process.\n  * Fix accuracy of Dot3 MAU types advertised and add support for\n    200G and 400G.\n  * Fix detection of wireless interfaces.\n\n- Update to version 1.0.20\n  Changes:\n  * Enable fast start unconditionally (and move its configuration\n    in \"configure lldp\").\n  * Make VLAN advertisements configurable.\n  Fix:\n  * Do not break zero-copy traffic on Linux.\n  * Fix crash on rapid addition/removal of interfaces.\n  * Fix management address selection when pattern is a negative\n    IP address.\n\n- Update to version 1.0.19\n  Changes:\n  * Add cvlan/svlan/tpmr capabilities.\n  * Add lldpctl_watch_sync_unblock to liblldpctl.\n  * Add C++ wrapper for lldpctl.\n  Fix:\n  * Fix AppArmor policy for /run/lldpd/lldpd.socket.lock.\n  * Do not query stats for a down interface on Linux.\n","modified":"2026-06-30T18:24:45.576327368Z","published":"2026-06-22T13:05:26Z","related":["CVE-2026-46433"],"upstream":["CVE-2026-46433"],"references":[{"type":"ADVISORY"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2026-46433"}],"affected":[{"package":{"name":"lldpd","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/lldpd&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.22-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"liblldpctl4":"1.0.22-bp160.1.1","lldpd":"1.0.22-bp160.1.1","lldpd-devel":"1.0.22-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:21146-1.json"}}],"schema_version":"1.7.5"}