CVE-2026-24184

Summary

NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause buffer overflow by sending crafted LLDP frames. A successful exploit of this vulnerability might lead to code execution.

Affected Software

VendorProductVersion RangeStatus
NVIDIACumulus Linux GA0.0 to 5.16affected
NVIDIACumulus Linux LTS0.0 to 5.11.5affected
NVIDIACumulus Linux LTS0.0 to 5.9.5affected

Weaknesses

  • CWE-120: CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References