๐Ÿ” CVE Alert

CVE-2026-75883

MEDIUM 6.8

PPPD buffer overflow in PEAP response code

CVSS Score
6.8
EPSS Score
0.0%
EPSS Percentile
0th

The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementing outgoing PEAP fragmentation. Thus a pppd process connecting to a server which requests PEAP authentication can be induced to corrupt global static data following the outpacket_buf array, most likely causing incorrect behavior or a crash.

CWE CWE-122
Vendor ppp project
Product ppp
Published Sep 18, 2026
Stay Ahead of the Next One

Get instant alerts for ppp project ppp

Be the first to know when new medium vulnerabilities affecting ppp project ppp are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Adjacent
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

PPP Project / ppp
0 โ‰ค 2.5.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/ppp-project/ppp/security/advisories/GHSA-rwr9-4vx8-vc35