CVE-2026-75883
6.8
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Summary
The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementing outgoing PEAP fragmentation. Thus a pppd process connecting to a server which requests PEAP authentication can be induced to corrupt global static data following the outpacket_buf array, most likely causing incorrect behavior or a crash.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| PPP Project | ppp | 0 <= 2.5.0 | affected |
| PPP Project | ppp | 2.5.4 | unaffected |
Weaknesses
- CWE-122: CWE-122 Heap-based buffer overflow
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.