GPU VulnDB

Database/Control plane, storage & DevOps

lldpd (802.1Q VLAN tag stripping in lldpd_decode): lldpd strips 802.1Q VLAN tags by memmove-ing the frame payload four

CVE-2026-46433Control plane, storage & DevOpscurated

Impact

lldpd strips 802.1Q VLAN tags by memmove-ing the frame payload four bytes left, and the byte count is not correctly bounded — so a crafted tagged frame drives a bad copy. Worth noting for anyone running lldpd on trunk ports, which in a leaf/spine fabric is most of them.

Who can reach it

Unauthenticated, adjacent — a crafted VLAN-tagged Ethernet frame on a port where lldpd is listening.

What to do

Upgrade lldpd to 1.0.22 or later and restart the daemon. Package upgrade plus service restart; on switch NOSes it comes with the image update.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.