CVE-2015-8011: Debian Linux
Critical severity, CVSS 9.8. EPSS: 5.5% chance of exploitation in the next 30 days.
Buffer overflow in the lldp_decode function in daemon/protocols/lldp.c in lldpd before 0.8.0 allows remote attackers to cause a denial of service (daemon crash) and possibly execute arbitrary code via vectors involving large management addresses and TLV boundaries.
Affected products
- Debian Debian Linux: version 9.0 only; version 10.0 only
- Fedoraproject Fedora: version 33 only
- Lldpd Project Lldpd: from 0.5.6, before 0.8.0 (fixed in 0.8.0)
Published 2020-01-28. Last modified 2026-06-17.