CVE-2026-24184 PUBLISHED

Assigner: nvidia
Reserved: 21.01.2026 Published: 18.08.2026 Updated: 18.08.2026

NVIDIA Cumulus Linux contains a vulnerability in the Link Layer Discovery Protocol (LLDP) daemon component, where an unauthenticated attacker on an adjacent network could cause buffer overflow by sending crafted LLDP frames. A successful exploit of this vulnerability might lead to code execution.

Metrics

CVSS Vector: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 7.5

Product Status

Vendor NVIDIA
Product Cumulus Linux GA
Versions Default: unaffected
  • Version 0.0 to 5.16 is affected
Vendor NVIDIA
Product Cumulus Linux LTS
Versions Default: unaffected
  • Version 0.0 to 5.11.5 is affected
Vendor NVIDIA
Product Cumulus Linux LTS
Versions Default: unaffected
  • Version 0.0 to 5.9.5 is affected

References

Problem Types

  • CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') CWE

Impacts

  • code execution