VDB
CISA-2023-41910
CISA-2023-41910
PUBLISHED
Reported by mitre · Published September 5, 2023
An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| n/a | n/a | n/a |
| n/a | n/a | n/a, n/a |
Timeline
- Sep 5, 2023 CVE Published
- Sep 30, 2024 CVE Updated
- Apr 26, 2026 Distribution Patch
- Apr 26, 2026 Security Advisory
References
- [debian-lts-announce] 20230922 [SECURITY] [DLA 3578-1] lldpd security update mailing-list
- DSA-5505 vendor-advisory