VYPR
Critical severity9.8NVD Advisory· Published Sep 5, 2023· Updated Jun 17, 2026

CVE-2023-41910

CVE-2023-41910

Description

An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdp_decode in daemon/protocols/cdp.c.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • lldpd/lldpddescription
  • lldpd/lldpd2 versions
    cpe:2.3:a:lldpd_project:lldpd:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:lldpd_project:lldpd:*:*:*:*:*:*:*:*range: <1.0.17
    • (no CPE)range: <1.0.17
  • osv-coords2 versions
    < 1.0.18-4.el9+ 1 more
    • (no CPE)range: < 1.0.18-4.el9
    • (no CPE)range: < 1.0.18-4.el9

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.