Lldpd is a lightweight link-layer discovery protocol daemon widely embedded in network switches, routers, and other infrastructure devices, where it handles parsing of untrusted network packets at a protocol parsing layer. Vulnerabilities in this vendor skew strongly toward critical-severity outcomes and cluster around memory-safety weaknesses including out-of-bounds reads and writes, buffer overflows, and resource-exhaustion flaws that are characteristic of C-based network parsers handling low-level frame data. Defenders should treat this vendor's advisories as high-priority for any switch or router fleet that runs the service, as the proximity to the data plane and the parsing complexity of link-layer protocols create sustained exposure to serious flaws; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Lldpd Project over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-41910CRITICAL An issue was discovered in lldpd before 1.0.17. By crafting a CDP PDU packet with specific CDP_TLV_ADDRESSES TLVs, a malicious actor can remotely force the lldpd daemon to perform | Sep 5, 2023 | 9.8 | 30 | NO | NO |
CVE-2015-8011CRITICAL Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execut | Jan 28, 2020 | 9.8 | 28 | NO | NO |
CVE-2026-46433MEDIUM lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling me | Jun 9, 2026 | 6.5 | 27 | NO | NO |
CVE-2021-43612HIGH In lldpd before 1.0.13, when decoding SONMP packets in the sonmp_decode function, it's possible to trigger an out-of-bounds heap read via short SONMP packets. | Apr 15, 2023 | 7.5 | 25 | NO | NO |
CVE-2020-27827HIGH A flaw was found in multiple versions of OpenvSwitch. Specially crafted LLDP packets can cause memory to be lost when allocating data to handle specific optional TLVs, potentially | Mar 18, 2021 | 7.5 | 25 | NO | NO |
CVE-2015-8012HIGH lldpd before 0.8.0 allows remote attackers to cause a denial of service (assertion failure and daemon crash) via a malformed packet. | Jan 28, 2020 | 7.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Lldpd Project.
Media articles that mention a CVE ID that affects a product developed by Lldpd Project — matched by CVE ID, not by vendor name.