mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.
History

Wed, 26 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 26 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
First Time appeared Freebsd
Freebsd freebsd
Vendors & Products Freebsd
Freebsd freebsd

Wed, 26 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Description mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.
Title ppp(8): missing length validation in mp_SetEnddisc()
Weaknesses CWE-122
CWE-130
References

cve-icon MITRE

Status: PUBLISHED

Assigner: freebsd

Published: 2026-08-26T05:28:17.570Z

Updated: 2026-08-27T03:57:12.382Z

Reserved: 2026-06-29T01:40:17.499Z

Link: CVE-2026-58097

cve-icon Vulnrichment

Updated: 2026-08-26T19:25:42.628Z

cve-icon NVD

Status : Undergoing Analysis

Published: 2026-08-26T06:16:26.700

Modified: 2026-08-27T04:16:44.743

Link: CVE-2026-58097

cve-icon Redhat

No data.