🔐 CVE Alert

CVE-2026-58096

CRITICAL 9.8

ppp(8): missing length validation in LcpDecodeConfig()

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.

CWE CWE-130 CWE-787
Vendor freebsd
Product freebsd
Published Aug 26, 2026
Last Updated Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for freebsd freebsd

Be the first to know when new critical vulnerabilities affecting freebsd freebsd are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

FreeBSD / FreeBSD
15.1-RELEASE < p3 15.0-RELEASE < p13 14.4-RELEASE < p9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
security.freebsd.org: https://security.freebsd.org/advisories/FreeBSD-SA-26:60.ppp.asc

Credits

Robert Morris Décio Brandão (0xDBJ) Joshua Rogers Reo Shiseki