NVIDIA Cumulus Linux - LLDP daemon: Crafted LLDP frames overflow a buffer in the LLDP daemon, reaching code execution
Impact
Crafted LLDP frames overflow a buffer in the LLDP daemon, reaching code execution on the switch from an unauthenticated attacker on an adjacent network. LLDP is processed from every connected port by default, so any compromised host in the rack can reach it.
Who can reach it
Adjacent network, unauthenticated. A single compromised server NIC sends LLDP frames to the leaf it is plugged into. This is a host-to-fabric escalation path.
What to do
Upgrade Cumulus Linux per bulletin 5817. Cost: switch reboot and link flap, sequenced leaf-by-leaf. Interim control: disable LLDP receive on host-facing ports if your tooling does not depend on it.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.