{"id":"AZL-89700","summary":"CVE-2026-46433 affecting package lldpd for versions less than 1.0.22-1","details":"lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift the frame payload 4 bytes left. The third argument (byte count) is s - 2 * ETHER_ADDR_LEN but should be s - 2 * ETHER_ADDR_LEN - 4, causing a 4-byte heap buffer over-read past the malloc(h_mtu) allocation when the received frame size equals the interface MTU. This issue has been patched in version 1.0.22.","modified":"2026-08-28T17:48:10.878501553Z","published":"2026-06-09T23:16:59Z","upstream":["CVE-2026-46433"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-46433"}],"affected":[{"package":{"name":"lldpd","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/lldpd"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.0.22-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-89700.json"}}],"schema_version":"1.9.0"}