CVE-2026-58095: ppp(8): incorrect length calculation in mp_Enddisc()
Published Aug 26, 2026
·Updated
mpEnddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer.
A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root.
Affected Software
1 affected component
ppp(8)
Event History
Aug 26, 2026
CVE Published
via MITRE·05:28 AM
Data Sourced
via MITRE·05:28 AM
DescriptionWeakness