CVE-2020-27827
published 2021-03-18CVE-2020-27827: A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific…
PriorityP340high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
3.23%
86.9th percentile
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
Affected
34 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | lldpd | < lldpd 1.0.8-1 (bookworm) | lldpd 1.0.8-1 (bookworm) |
| debian | openvswitch | < lldpd 1.0.8-1 (bookworm) | lldpd 1.0.8-1 (bookworm) |
| fedoraproject | fedora | — | — |
| lldp | openvswitch | — | — |
| lldpd_project | lldpd | < 1.0.8 | 1.0.8 |
| lldpd_project | lldpd | >= 0 < 1.0.8-1 | 1.0.8-1 |
| lldpd_project | lldpd | >= 0 < 1.0.8-1 | 1.0.8-1 |
| lldpd_project | lldpd | >= 0 < 1.0.8-1 | 1.0.8-1 |
| lldpd_project | lldpd | >= 0 < 1.0.8-1 | 1.0.8-1 |
| msrc | cbl2_lldpd_1.0.14-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_lldpd_1.0.4-3_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_openvswitch_2.12.3-2_on_cbl_mariner_1.0 | — | — |
| openvswitch | openvswitch | >= 0 < 2.15.0~git20210104.def6eb1ea+dfsg1-4 | 2.15.0~git20210104.def6eb1ea+dfsg1-4 |
| openvswitch | openvswitch | >= 0 < 2.15.0~git20210104.def6eb1ea+dfsg1-4 | 2.15.0~git20210104.def6eb1ea+dfsg1-4 |
| openvswitch | openvswitch | >= 0 < 2.15.0~git20210104.def6eb1ea+dfsg1-4 | 2.15.0~git20210104.def6eb1ea+dfsg1-4 |
| openvswitch | openvswitch | >= 0 < 2.15.0~git20210104.def6eb1ea+dfsg1-4 | 2.15.0~git20210104.def6eb1ea+dfsg1-4 |
| openvswitch | openvswitch | >= 2.10.0 < 2.10.6 | 2.10.6 |
| openvswitch | openvswitch | >= 2.11.0 < 2.11.5 | 2.11.5 |
| openvswitch | openvswitch | >= 2.12.0 < 2.12.2 | 2.12.2 |
| openvswitch | openvswitch | >= 2.13.0 < 2.13.2 | 2.13.2 |
| openvswitch | openvswitch | >= 2.14.0 < 2.14.1 | 2.14.1 |
| openvswitch | openvswitch | >= 2.6.0 < 2.6.9 | 2.6.9 |
| openvswitch | openvswitch | >= 2.7.0 < 2.7.12 | 2.7.12 |
| openvswitch | openvswitch | >= 2.8.0 < 2.8.10 | 2.8.10 |
| openvswitch | openvswitch | >= 2.9.0 < 2.9.8 | 2.9.8 |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_redhat7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Industrial Products LLDP (Update D)
cisa_ics·2022-08-11
Siemens Industrial Products LLDP (Update D)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Industrial Products LLDP (Update D)
Last RevisedAugust 18, 2022
Alert CodeICSA-21-194-07
## As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: Industrial Products
- Vulnerabilities: C
Microsoft
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs potentially causing a denial of s
vendor_msrc·2021-03-09·CVSS 7.5
CVE-2020-27827 [HIGH] CWE-400 A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs potentially causing a denial of s
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more in
Ubuntu
Open vSwitch vulnerabilities
vendor_ubuntu·2021-01-13
CVE-2015-8011 Open vSwitch vulnerabilities
Title: Open vSwitch vulnerabilities
Summary: Several security issues were fixed in Open vSwitch.
Jonas Rudloff discovered that Open vSwitch incorrectly handled certain
malformed LLDP packets. A remote attacker could use this issue to cause
Open vSwitch to crash, resulting in a denial of service, or possibly
execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
lldp/openvswitch: denial of service via externally triggered memory leak
vendor_redhat·2021-01-13·CVSS 7.5
CVE-2020-27827 [HIGH] CWE-400 lldp/openvswitch: denial of service via externally triggered memory leak
lldp/openvswitch: denial of service via externally triggered memory leak
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
A flaw was found in multiple versions of Open vSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
Statement: Red Hat OpenStack Platform 13's openvswitch package will receive it's fixes from Fast Datapath.
Package: openvswitch2.10 (Fast Datapath for RHEL 7) - Out
Debian
CVE-2020-27827: lldpd - A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP pac...
vendor_debian·2020·CVSS 7.5
CVE-2020-27827 [HIGH] CVE-2020-27827: lldpd - A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP pac...
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
Scope: local
bookworm: resolved (fixed in 1.0.8-1)
bullseye: resolved (fixed in 1.0.8-1)
forky: resolved (fixed in 1.0.8-1)
sid: resolved (fixed in 1.0.8-1)
trixie: resolved (fixed in 1.0.8-1)
GHSA
GHSA-m3mq-x6x3-4537: A flaw was found in multiple versions of OpenvSwitch
ghsa_unreviewed·2022-05-24
CVE-2020-27827 [HIGH] CWE-400 GHSA-m3mq-x6x3-4537: A flaw was found in multiple versions of OpenvSwitch
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
OSV
CVE-2020-27827: A flaw was found in multiple versions of OpenvSwitch
osv·2021-03-18·CVSS 7.5
CVE-2020-27827 [HIGH] CVE-2020-27827: A flaw was found in multiple versions of OpenvSwitch
A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially causing a denial of service. The highest threat from this vulnerability is to system availability.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://bugzilla.redhat.com/show_bug.cgi?id=1921438https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdfhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3T5XHPOGIPWCRRPJUE6P3HVC5PTSD5JS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYA4AMJXCNF6UPFG36L2TPPT32C242SP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SKQWHG2SZJZSGC7PXVDAEJYBN7ESDR7D/https://mail.openvswitch.org/pipermail/ovs-dev/2021-January/379471.htmlhttps://security.gentoo.org/glsa/202311-16https://us-cert.cisa.gov/ics/advisories/icsa-21-194-07https://bugzilla.redhat.com/show_bug.cgi?id=1921438https://cert-portal.siemens.com/productcert/pdf/ssa-941426.pdfhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3T5XHPOGIPWCRRPJUE6P3HVC5PTSD5JS/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/JYA4AMJXCNF6UPFG36L2TPPT32C242SP/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/SKQWHG2SZJZSGC7PXVDAEJYBN7ESDR7D/https://mail.openvswitch.org/pipermail/ovs-dev/2021-January/379471.htmlhttps://security.gentoo.org/glsa/202311-16https://us-cert.cisa.gov/ics/advisories/icsa-21-194-07
2021-03-18
Published