🔐 CVE Alert

CVE-2026-58097

UNKNOWN 0.0

ppp(8): missing length validation in mp_SetEnddisc()

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.

CWE CWE-130 CWE-122
Vendor freebsd
Product freebsd
Published Aug 26, 2026
Stay Ahead of the Next One

Get instant alerts for freebsd freebsd

Be the first to know when new unknown vulnerabilities affecting freebsd freebsd are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

FreeBSD / FreeBSD
15.1-RELEASE < p3 15.0-RELEASE < p13 14.4-RELEASE < p9

References

NVD ↗ CVE.org ↗ EPSS Data ↗
security.freebsd.org: https://security.freebsd.org/advisories/FreeBSD-SA-26:60.ppp.asc

Credits

Robert Morris Décio Brandão (0xDBJ) Joshua Rogers Reo Shiseki