An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.
CVSS Details
- CVSS 3.1 Base Score: 9.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alma_linux | — | Upgrade lldpdUpgrade lldpd-devel | Nov 19, 2024 | Sep 5, 2023 |
| Debian | — | Upgrade lldpd | Sep 25, 2023 | Sep 5, 2023 |
| Oracle_linux | — | Upgrade lldpdUpgrade lldpd-devel | Nov 21, 2024 | Sep 5, 2023 |
| Redhat_linux | — | Upgrade lldpd-develUpgrade lldpd-debugsourceUpgrade lldpdUpgrade lldpd-debuginfoNo solution exists | Nov 13, 2024 | Sep 5, 2023 |
| Rocky_linux | — | Upgrade lldpd-develUpgrade lldpd-debugsourceUpgrade lldpdUpgrade lldpd-debuginfo | Mar 18, 2025 | Sep 5, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub