Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-46433

Опубликовано: 09 июн. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the frame payload 4 bytes left. The third argument (byte count) is s - 2 * ETHER_ADDR_LEN but should be s - 2 * ETHER_ADDR_LEN - 4, causing a 4-byte heap buffer over-read past the malloc(h_mtu) allocation when the received frame size equals the interface MTU. This issue has been patched in version 1.0.22.

A flaw was found in lldpd, an implementation of IEEE 802.1ab (LLDP). A remote attacker on the adjacent network can send specially crafted Ethernet frames with 802.1Q VLAN (Virtual Local Area Network) tags. This can cause a 4-byte heap buffer over-read, leading to a denial of service (DoS) due to an application crash. This vulnerability occurs when the received frame size equals the interface Maximum Transmission Unit (MTU).

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10lldpdFix deferred
Red Hat Enterprise Linux 8lldpdFix deferred
Red Hat Enterprise Linux 9lldpdFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-131
https://bugzilla.redhat.com/show_bug.cgi?id=2487363lldpd: lldpd: Denial of Service due to heap buffer over-read when processing VLAN-tagged Ethernet frames

EPSS

Процентиль: 13%
0.00225
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
около 2 месяцев назад

lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the frame payload 4 bytes left. The third argument (byte count) is s - 2 * ETHER_ADDR_LEN but should be s - 2 * ETHER_ADDR_LEN - 4, causing a 4-byte heap buffer over-read past the malloc(h_mtu) allocation when the received frame size equals the interface MTU. This issue has been patched in version 1.0.22.

CVSS3: 6.5
nvd
около 2 месяцев назад

lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the frame payload 4 bytes left. The third argument (byte count) is s - 2 * ETHER_ADDR_LEN but should be s - 2 * ETHER_ADDR_LEN - 4, causing a 4-byte heap buffer over-read past the malloc(h_mtu) allocation when the received frame size equals the interface MTU. This issue has been patched in version 1.0.22.

CVSS3: 6.5
msrc
около 2 месяцев назад

lldpd: Heap OOB Read in VLAN Decapsulation memmove

CVSS3: 6.5
debian
около 2 месяцев назад

lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1. ...

suse-cvrf
около 1 месяца назад

Security update for lldpd

EPSS

Процентиль: 13%
0.00225
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-46433