<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Lldpd on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/lldpd/</link><description>Recent content in Lldpd on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Sun, 15 Jun 2025 08:42:41 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/lldpd/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-46433: lldpd Heap OOB Read in Azure</title><link>https://zxcloudsecurity.co.uk/posts/azure-lldpd-heap-oob-read-vlan-decapsulation-cve-2026-46433/</link><pubDate>Mon, 15 Jun 2026 08:42:41 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/azure-lldpd-heap-oob-read-vlan-decapsulation-cve-2026-46433/</guid><description>CVE-2026-46433 is a heap out-of-bounds read in lldpd affecting Azure environments. Learn the impact and remediation steps for cloud security teams.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46433">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2026-46433 is a heap out-of-bounds read vulnerability in lldpd, the open-source Link Layer Discovery Protocol daemon, triggered during VLAN decapsulation via a flawed memmove operation. An attacker able to send crafted LLDP frames on an adjacent network could exploit this to read sensitive memory contents, potentially leaking information from affected hosts. This affects Azure environments where lldpd is running on underlying infrastructure or customer-managed VMs.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Audit your Azure VMs and container hosts for any running instances of lldpd and apply vendor patches promptly; where lldpd is unnecessary, disable or remove it entirely to reduce attack surface, particularly on network-adjacent workloads.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-46433">CVE-2026-46433 lldpd: Heap OOB Read in VLAN Decapsulation memmove</a></p>
]]></content:encoded></item></channel></rss>