NVIDIA Cumulus Linux - LLDP daemon: Crafted LLDP frames overflow a buffer in the LLDP daemon, reaching code execution
Impact
Crafted LLDP frames overflow a buffer in the LLDP daemon, reaching code execution on the switch from an unauthenticated attacker on an adjacent network. LLDP is processed from every connected port by default, so any compromised host in the rack can reach it.
Who can reach it
Adjacent network, unauthenticated. A single compromised server NIC sends LLDP frames to the leaf it is plugged into. This is a host-to-fabric escalation path.
What to do
Upgrade Cumulus Linux per bulletin 5817. Cost: switch reboot and link flap, sequenced leaf-by-leaf. Interim control: disable LLDP receive on host-facing ports if your tooling does not depend on it.
References
Related entries
- Triton Inference Server: Arbitrary file access via unsafe path operationsCVE-2026-24209 · Triton Inference ServerHigh
- Triton Inference Server: DoS / memory corruption (integer overflow in buffer allocation)CVE-2026-24210 · Triton Inference ServerHigh
- Isaac Launchable: Info disclosure (unencrypted sensitive data in transit)CVE-2026-24212 · Isaac LaunchableHigh
- NVIDIA Dynamo: MITM via improper TLS certificate verificationCVE-2026-24255 · NVIDIA DynamoHigh
- Triton Inference Server: DoS via improper exception handlingCVE-2026-24264 · Triton Inference ServerHigh
- TensorRT-LLM: RCE potential (OOB write in tensor manipulation)CVE-2026-47471 · TensorRT-LLMHigh
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.