An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade lldpdUpgrade lldpd-devel | Nov 19, 2024 | Sep 5, 2023 |
| Debian | — | Upgrade lldpd | Sep 25, 2023 | Sep 5, 2023 |
| Oracle_linux | — | Upgrade lldpd-develUpgrade lldpd | Nov 21, 2024 | Sep 5, 2023 |
| Redhat_linux | — | Upgrade lldpd-develUpgrade lldpd-debugsourceUpgrade lldpdNo solution existsUpgrade lldpd-debuginfo | Nov 13, 2024 | Sep 5, 2023 |
| Rocky_linux | — | Upgrade lldpd-debugsourceUpgrade lldpd-develUpgrade lldpdUpgrade lldpd-debuginfo | Mar 18, 2025 | Sep 5, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub