Executive brief
NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon, which is a networking component used for device discovery on local networks. An attacker on an adjacent network could send specially crafted LLDP frames to trigger a buffer overflow and potentially execute arbitrary code on affected network devices, compromising system integrity and availability.
Technical details
The vulnerability is a buffer overflow in the LLDP daemon component of Cumulus Linux. An unauthenticated attacker positioned on an adjacent network can exploit this vulnerability by crafting malicious LLDP frames. The attack requires network proximity but no authentication or credentials. Successful exploitation could result in remote code execution with the privileges of the LLDP daemon process, potentially allowing full system compromise. Patch availability is indicated by the publication of NVIDIA's security advisory and associated JSON representations, though specific patched version numbers are not detailed in the provided excerpt.
Affected products
- NVIDIA Cumulus Linux <UNKNOWN>
Timeline
- 2026-08-18: disclosed