CVE-2026-58096
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.55%
- CWE
- CWE-130, CWE-787
- Published
- 2026-08-26
- Last modified
- 2026-08-27
Affected products
- FreeBSD FreeBSD
- FreeBSD FreeBSD
- FreeBSD FreeBSD
Weakness type
Related vulnerabilities
- CVE-2026-71337 — Windows Storage Management Provider Elevation of Privilege Vulnerability
- CVE-2026-5706 — Buffer overflow in Bluetooth Mesh SDK when handling extended advertisements
- CVE-2026-71402 — wicked: out-of-bounds read in the DHCPv4 option parser due to payload length taken from the IP total length
- CVE-2026-81575 — Missing Sanity Checks for Buffer Lengths
- CVE-2026-58097 — ppp(8): missing length validation in mp_SetEnddisc()
- CVE-2026-14587 — Unathenticated connection can hold Bolt channel open
- CVE-2026-67292 — FreeRDP before 3.29.0 WebSocket Ping Buffer Over-disclosure
- CVE-2026-26081 — HAProxy Community Edition 3.0 through 3.3 before 3.3.3 lacks a length check for the NEW_TOKEN...