An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade lldpd-develUpgrade lldpd | Nov 19, 2024 | Sep 5, 2023 |
| Debian | — | Upgrade lldpd | Sep 25, 2023 | Sep 5, 2023 |
| Oracle_linux | — | Upgrade lldpdUpgrade lldpd-devel | Nov 21, 2024 | Sep 5, 2023 |
| Redhat_linux | — | No solution existsUpgrade lldpd-debuginfoUpgrade lldpdUpgrade lldpd-develUpgrade lldpd-debugsource | Nov 13, 2024 | Sep 5, 2023 |
| Rocky_linux | — | Upgrade lldpd-debuginfoUpgrade lldpdUpgrade lldpd-develUpgrade lldpd-debugsource | Mar 18, 2025 | Sep 5, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub