Database/Firmware, BMC & network fabric
lldpd (CDP PDU parser, cdp_decode): A crafted CDP PDU with specific CDP_TLV_ADDRESSES TLVs forces lldpd
Impact
A crafted CDP PDU with specific CDP_TLV_ADDRESSES TLVs forces lldpd into an out-of-bounds heap read. lldpd is what runs on Linux-based switch OSes and on servers that advertise link topology, it runs as root, and it accepts input from any directly attached device with no authentication whatsoever. In a GPU cluster where LLDP is used to verify rail-optimized cabling, lldpd is running on every node and every switch.
Who can reach it
Unauthenticated, adjacent — a single crafted frame from a directly connected device. Any tenant bare-metal node can attack the switch or the neighbours it is cabled to.
What to do
Upgrade lldpd to 1.0.17 or later and restart the daemon — a package upgrade with a service restart, no reboot, no switch reload. On appliance NOSes this arrives as a NOS image update instead. Cheap fix; the reason it lingers is that nobody inventories lldpd versions.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.