Logo
vulnerabilityCVE-2026-46433
Name
CVE-2026-46433
Source
NVD ( link)Debian ( link)
Description
lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the frame payload 4 bytes left. The third argument (byte count) is s - 2 * ETHER_ADDR_LEN but should be s - 2 * ETHER_ADDR_LEN - 4, causing a 4-byte heap buffer over-read past the malloc(h_mtu) allocation when the received frame size equals the interface MTU. This issue has been patched in version 1.0.22.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
lldpd
Exploitable

Vulnerability Ratings#


6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
1.0.18
Exploitable
buildroot
master
1.0.20
Exploitable
openwrt
master
1.0.22-r1
Not Affected
openwrt
openwrt-25.12
1.0.20-r1
Exploitable
yocto
kirkstone
1.0.8
Exploitable
yocto
master
1.0.22
Not Affected