GPU VulnDB

Database/Firmware, BMC & network fabric

lldpd (CDP PDU parser, cdp_decode): A crafted CDP PDU with specific CDP_TLV_ADDRESSES TLVs forces lldpd

CVE-2023-41910Firmware, BMC & network fabriccurated

Impact

A crafted CDP PDU with specific CDP_TLV_ADDRESSES TLVs forces lldpd into an out-of-bounds heap read. lldpd is what runs on Linux-based switch OSes and on servers that advertise link topology, it runs as root, and it accepts input from any directly attached device with no authentication whatsoever. In a GPU cluster where LLDP is used to verify rail-optimized cabling, lldpd is running on every node and every switch.

Who can reach it

Unauthenticated, adjacent — a single crafted frame from a directly connected device. Any tenant bare-metal node can attack the switch or the neighbours it is cabled to.

What to do

Upgrade lldpd to 1.0.17 or later and restart the daemon — a package upgrade with a service restart, no reboot, no switch reload. On appliance NOSes this arrives as a NOS image update instead. Cheap fix; the reason it lingers is that nobody inventories lldpd versions.

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.