Database/Firmware, BMC & network fabric
lldpd (CDP PDU parser, cdp_decode): A crafted CDP PDU with specific CDP_TLV_ADDRESSES TLVs forces lldpd
Impact
A crafted CDP PDU with specific CDP_TLV_ADDRESSES TLVs forces lldpd into an out-of-bounds heap read. lldpd is what runs on Linux-based switch OSes and on servers that advertise link topology, it runs as root, and it accepts input from any directly attached device with no authentication whatsoever. In a GPU cluster where LLDP is used to verify rail-optimized cabling, lldpd is running on every node and every switch.
Who can reach it
Unauthenticated, adjacent — a single crafted frame from a directly connected device. Any tenant bare-metal node can attack the switch or the neighbours it is cabled to.
What to do
Upgrade lldpd to 1.0.17 or later and restart the daemon — a package upgrade with a service restart, no reboot, no switch reload. On appliance NOSes this arrives as a NOS image update instead. Cheap fix; the reason it lingers is that nobody inventories lldpd versions.
References
Related entries
- Broadcom LSI Storage Authority (LSA) / Intel RAID Web Console 3 (RWC3)CVE-2023-4323 · Broadcom LSI Storage Authority (LSA) / Intel RAID Web Console 3 (RWC3) - management service for MegaRAID and LSI HBA…Critical
- ATEN PE6208 switched PDU: The PDU ships with a default telnet account and never forces the operator to changeCVE-2023-43845 · ATEN PE6208 switched PDUCritical
- Linux kernel (drivers/infiniband/ulp/srp): The SRP abort handler completes the SCSI command itself, after which theCVE-2023-52515 · Linux kernel (drivers/infiniband/ulp/srp)Critical
- Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/xsk): An RX buffer on the legacy receive queue is releasedCVE-2023-54223 · Linux kernel (drivers/net/ethernet/mellanox/mlx5/core/en/xsk)Critical
- Supermicro BMC firmware web/management service (X11/X12/X13/H12/H13/B12/B13, CMM6): An attacker who never authenticatesCVE-2024-36435 · Supermicro BMC firmware web/management service (X11/X12/X13/H12/H13/B12/B13, CMM6)Critical
- Linux kernel (drivers/infiniband/ulp/rtrs): The RTRS server builds an RDMA work request around a scatter-gather listCVE-2024-36476 · Linux kernel (drivers/infiniband/ulp/rtrs)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.