CVE-2023-41910: Critical severity centos lldpad vulnerability
An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDPTLVADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory. This occurs in cdpdecode in daemon/protocols/cdp.c.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-41910?
CVE-2023-41910 is a vulnerability in the lldpd software version 1.0.17 and below, where a malicious actor can remotely force the lldpd daemon to perform an out-of-bounds read on heap memory.
What is the severity of CVE-2023-41910?
CVE-2023-41910 has a severity rating of 9.8 (critical).
How does CVE-2023-41910 affect the lldpd software?
CVE-2023-41910 affects lldpd software versions 1.0.17 and below, allowing a malicious actor to remotely trigger an out-of-bounds read on heap memory by crafting a specific CDP PDU packet.
How can I fix CVE-2023-41910?
To fix CVE-2023-41910, it is recommended to update the lldpd software to version 1.0.17 or higher.
Where can I find more information about CVE-2023-41910?
More information about CVE-2023-41910 can be found in the following references: [GitHub Commit](https://github.com/lldpd/lldpd/commit/a9aeabdf879c25c584852a0bb5523837632f099b), [Debian Security Tracker](https://security-tracker.debian.org/tracker/CVE-2023-41910), [lldpd Releases](https://github.com/lldpd/lldpd/releases/tag/1.0.17).