Vulnerability Description
lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the frame payload 4 bytes left. The third argument (byte count) is s - 2 * ETHER_ADDR_LEN but should be s - 2 * ETHER_ADDR_LEN - 4, causing a 4-byte heap buffer over-read past the malloc(h_mtu) allocation when the received frame size equals the interface MTU. This issue has been patched in version 1.0.22.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Lldpd Project | Lldpd | < 1.0.22 |
Related Weaknesses (CWE)
References
- https://github.com/lldpd/lldpd/commit/ca931be63a9cae0fcd8e9b6ae4e916d49f141cd6Patch
- https://github.com/lldpd/lldpd/pull/787Issue TrackingPatch
- https://github.com/lldpd/lldpd/releases/tag/1.0.22ProductRelease Notes
- https://github.com/lldpd/lldpd/security/advisories/GHSA-2g8p-2h3j-63m3Vendor Advisory
FAQ
What is CVE-2026-46433?
CVE-2026-46433 is a vulnerability with a CVSS score of 6.5 (MEDIUM). lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the...
How severe is CVE-2026-46433?
CVE-2026-46433 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-46433?
Check the references section above for vendor advisories and patch information. Affected products include: Lldpd Project Lldpd.