CVE-2020-27827
18.03.2021, 17:15
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.Enginsight
Vendor | Product | Version |
---|---|---|
lldpd_project | lldpd | 𝑥 < 1.0.8 |
openvswitch | openvswitch | 2.6.0 ≤ 𝑥 < 2.6.9 |
openvswitch | openvswitch | 2.7.0 ≤ 𝑥 < 2.7.12 |
openvswitch | openvswitch | 2.8.0 ≤ 𝑥 < 2.8.10 |
openvswitch | openvswitch | 2.9.0 ≤ 𝑥 < 2.9.8 |
openvswitch | openvswitch | 2.10.0 ≤ 𝑥 < 2.10.6 |
openvswitch | openvswitch | 2.11.0 ≤ 𝑥 < 2.11.5 |
openvswitch | openvswitch | 2.12.0 ≤ 𝑥 < 2.12.2 |
openvswitch | openvswitch | 2.13.0 ≤ 𝑥 < 2.13.2 |
openvswitch | openvswitch | 2.14.0 ≤ 𝑥 < 2.14.1 |
redhat | openshift_container_platform | 4.0 |
redhat | virtualization | 4.0 |
redhat | enterprise_linux | 7.0 |
redhat | enterprise_linux | 8.0 |
siemens | simatic_hmi_unified_comfort_panels_firmware | 𝑥 < 17 |
siemens | simatic_net_cp_1243-1_firmware | - |
siemens | simatic_net_cp_1243-8_irc_firmware | - |
siemens | simatic_net_cp_1542sp-1_firmware | - |
siemens | simatic_net_cp_1542sp-1_irc_firmware | - |
siemens | simatic_net_cp_1543-1_firmware | - |
siemens | simatic_net_cp_1543sp-1_firmware | - |
siemens | simatic_net_cp_1545-1_firmware | - |
siemens | tim_1531_irc_firmware | 𝑥 < 2.2 |
siemens | sinumerik_one_firmware | 𝑥 < 2.0.1 |
𝑥
= Vulnerable software versions

Debian Releases
Debian Product | |||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
lldpd |
| ||||||||||||||
openvswitch |
|

Ubuntu Releases
Ubuntu Product | |||||||||||||||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
lldpd |
| ||||||||||||||||||||||||
openvswitch |
|
References