Skip to content

Upgrade lldpd to address CVE-2021-43612#37

Merged
amstewart merged 6 commits intoni:nilrt/master/kirkstonefrom
gratian:dev/nilrt/master/kirkstone-lldpd-upgrades
Jun 13, 2023
Merged

Upgrade lldpd to address CVE-2021-43612#37
amstewart merged 6 commits intoni:nilrt/master/kirkstonefrom
gratian:dev/nilrt/master/kirkstone-lldpd-upgrades

Conversation

@gratian
Copy link

@gratian gratian commented Jun 12, 2023

lldpd in kirkstone has a CVE CVE-2021-43612. This was fixed by lldpd upstream in version 1.0.17 and upstream meta-openembedded layer upgraded to this version.

Cherry pick this upgrade (and intermediate commits) into our kirkstone branch in order to address the CVE mentioned above.

AD bug #2408711

Note to maintainers

Testing

  • bitbake lldpd
  • bitbake nilrt-base-system-image
  • bitbake nilrt-safemode-rootfs

harshalgohel and others added 6 commits June 9, 2023 16:01
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit dd8d5e8)
Signed-off-by: Gratian Crisan <gratian.crisan@ni.com>
Add github-releases to make new releases discoverable.

Signed-off-by: Alex Kiernan <alex.kiernan@gmail.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit c782674)
Signed-off-by: Gratian Crisan <gratian.crisan@ni.com>
Signed-off-by: Xiangyu Chen <xiangyu.chen@eng.windriver.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 7fe87be)
Signed-off-by: Gratian Crisan <gratian.crisan@ni.com>
Fix:
--------
    Do not use 00:00:00:00:00:00 as chassis ID.
    Do not busy loop when an interface with a neighbor disappears.

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit a56dcf4)
Signed-off-by: Gratian Crisan <gratian.crisan@ni.com>
The checksum was not updated when the recipe version was stepped.

Also simplify the SRC_URI by replacing "${BPN}-${PV}" with "${BP}".

Signed-off-by: Peter Kjellerstedt <peter.kjellerstedt@axis.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit 9cbd247)
Signed-off-by: Gratian Crisan <gratian.crisan@ni.com>
* Fix:
    Read overflow when parsing CDP addresses.
    Don't output empty lines on configure commands.

Signed-off-by: Wang Mingyu <wangmy@fujitsu.com>
Signed-off-by: Khem Raj <raj.khem@gmail.com>
(cherry picked from commit d74aec2)
Signed-off-by: Gratian Crisan <gratian.crisan@ni.com>
@amstewart amstewart merged commit 66f11ae into ni:nilrt/master/kirkstone Jun 13, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

7 participants