๐Ÿ” CVE Alert

CVE-2026-46433

MEDIUM 6.5

lldpd: Heap OOB Read in VLAN Decapsulation memmove

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the frame payload 4 bytes left. The third argument (byte count) is s - 2 * ETHER_ADDR_LEN but should be s - 2 * ETHER_ADDR_LEN - 4, causing a 4-byte heap buffer over-read past the malloc(h_mtu) allocation when the received frame size equals the interface MTU. This issue has been patched in version 1.0.22.

CWE CWE-125
Vendor lldpd
Product lldpd
Published Jun 9, 2026
Stay Ahead of the Next One

Get instant alerts for lldpd lldpd

Be the first to know when new medium vulnerabilities affecting lldpd lldpd are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
Adjacent
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High

Affected Versions

lldpd / lldpd
< 1.0.22

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/lldpd/lldpd/security/advisories/GHSA-2g8p-2h3j-63m3 github.com: https://github.com/lldpd/lldpd/pull/787 github.com: https://github.com/lldpd/lldpd/commit/ca931be63a9cae0fcd8e9b6ae4e916d49f141cd6 github.com: https://github.com/lldpd/lldpd/releases/tag/1.0.22