What is CVE-2026-24184?
A critical vulnerability exists in the Link Layer Discovery Protocol (LLDP) daemon within NVIDIA Cumulus Linux. An unauthenticated attacker on an adjacent network can trigger a buffer overflow by sending crafted LLDP frames, potentially leading to remote code execution. Affected network devices require immediate patching.
Azərbaycanca: NVIDIA Cumulus Linux əməliyyat sistemində yerləşən Link Layer Discovery Protocol (LLDP) xidmətində kritik boşluq aşkarlanıb. Təcavüzkar qonşu şəbəkədən xüsusi hazırlanmış LLDP çərçivələri göndərərək autentifikasiya olmadan `buffer overflow` yarada və potensial olaraq uzaqdan kod icrası (`code execution`) əldə edə bilər. Təsirə məruz qalan şəbəkə avadanlıqları dərhal yamalanmalıdır.
Related CVEs
link basis: same weakness class CWE-119
FAQ1
Does exploiting CVE-2026-24184 in NVIDIA Cumulus Linux require authentication?
No, an unauthenticated attacker on an adjacent network can exploit this vulnerability by sending crafted LLDP frames.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.