CVE-2026-58096

Summary

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write.

A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.

Affected Software

VendorProductVersion RangeStatus
FreeBSDFreeBSD15.1-RELEASE < p3affected
FreeBSDFreeBSD15.0-RELEASE < p13affected
FreeBSDFreeBSD14.4-RELEASE < p9affected

Weaknesses

  • CWE-130: CWE-130: Improper Handling of Length Parameter Inconsistency
  • CWE-787: CWE-787: Out-of-bounds Write

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References