Database/Control plane, storage & DevOps

lldpd (802.1Q VLAN tag stripping in lldpd_decode): lldpd strips 802.1Q VLAN tags by memmove-ing the frame payload four
CVE-2026-46433Control plane, storage & DevOpscurated
Impact
lldpd strips 802.1Q VLAN tags by memmove-ing the frame payload four bytes left, and the byte count is not correctly bounded — so a crafted tagged frame drives a bad copy. Worth noting for anyone running lldpd on trunk ports, which in a leaf/spine fabric is most of them.
Who can reach it
Unauthenticated, adjacent — a crafted VLAN-tagged Ethernet frame on a port where lldpd is listening.
What to do
Upgrade lldpd to 1.0.22 or later and restart the daemon. Package upgrade plus service restart; on switch NOSes it comes with the image update.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.