Buffer Overflow in Link Layer Discovery Protocol Daemon in NVIDIA Cumulus Linux
CVE-2026-24184

7.5HIGH

Key Information:

Vendor

Nvidia

Vendor
CVE Published:
18 August 2026

What is CVE-2026-24184?

The Link Layer Discovery Protocol (LLDP) daemon in NVIDIA Cumulus Linux has a buffer overflow vulnerability that an unauthenticated attacker on an adjacent network could exploit by sending specially crafted LLDP frames. This could lead to potential code execution, allowing the attacker to manipulate the affected system.

Affected Version(s)

Cumulus Linux GA Cumulus Linux 0.0 to 5.16

Cumulus Linux LTS Cumulus Linux(5.11) 0.0 to 5.11.5

Cumulus Linux LTS Cumulus Linux(5.9) 0.0 to 5.9.5

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.