GPU VulnDB

Database/Firmware, BMC & network fabric

Cisco NX-OS / FXOS (LLDP parser): FABRIC DOS: a malformed LLDP frame reloads the switch

CVE-2018-0395Firmware, BMC & network fabriccurated

Impact

FABRIC DOS: a malformed LLDP frame reloads the switch. LLDP is enabled by default on essentially every fabric port and is unauthenticated by design, so any host on any port can drop its leaf. In a training cluster a single leaf reload takes out a whole rack of GPUs mid-job.

Who can reach it

Unauthenticated, adjacent — a single crafted frame from a directly connected host.

What to do

NX-OS upgrade plus reload. Interim: disable LLDP on tenant-facing ports. Note that if you use LLDP for cabling verification (common in GPU builds, to prove the rail-optimized topology is wired right) disabling it costs you that check, so most operators patch rather than disable.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.