A flaw was found in NetworkManager. When a system running NetworkManager with DEBUG logs enabled and an interface eth1 configured with LLDP enabled, a malicious user could inject a malformed LLDP packet. NetworkManager would crash, leading to a denial of service.
{
"binaries": [
{
"binary_name": "gir1.2-nm-1.0",
"binary_version": "1.46.0-1ubuntu2.4"
},
{
"binary_name": "libnm-dev",
"binary_version": "1.46.0-1ubuntu2.4"
},
{
"binary_name": "libnm0",
"binary_version": "1.46.0-1ubuntu2.4"
},
{
"binary_name": "network-manager",
"binary_version": "1.46.0-1ubuntu2.4"
},
{
"binary_name": "network-manager-config-connectivity-debian",
"binary_version": "1.46.0-1ubuntu2.4"
},
{
"binary_name": "network-manager-config-connectivity-ubuntu",
"binary_version": "1.46.0-1ubuntu2.4"
},
{
"binary_name": "network-manager-dev",
"binary_version": "1.46.0-1ubuntu2.4"
}
],
"priority_reason": "DoS only when DEBUG and LLDP are enabled"
}