"Multiple versions of Open vSwitch are vulnerable to crafted LLDP packets causing denial of service, and data underflow attacks. Triggering the vulnerabilities requires LLDP processing to be enabled for a specific port. Open vSwitch versions prior to 2.4.0 are not vulnerable. The Common Vulnerabilities and Exposures project (cve.mitre.org) did not assign the identifier to this issue yet. The identifier will be communicated separately. This issue does not affect the `lldpd' project, although they share a code base. The issue is related to parsing the Auto Attach TLVs, which is specific to the Open vSwitch implementation." Please bump to 2.15.7, 2.17.5.