CVE-2026-58096
ppp(8): missing length validation in LcpDecodeConfig()
CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
| CWE | CWE-130 CWE-787 |
| Vendor | freebsd |
| Product | freebsd |
| Published | Aug 26, 2026 |
| Last Updated | Aug 26, 2026 |
Stay Ahead of the Next One
Get instant alerts for freebsd freebsd
Be the first to know when new critical vulnerabilities affecting freebsd freebsd are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
FreeBSD / FreeBSD
15.1-RELEASE < p3 15.0-RELEASE < p13 14.4-RELEASE < p9
References
Credits
Robert Morris Décio Brandão (0xDBJ) Joshua Rogers Reo Shiseki