Описание
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write.
A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
EPSS
Процентиль: 44%
0.0055
Низкий
8.8 High
CVSS3
Дефекты
CWE-130
Связанные уязвимости
CVSS3: 9.8
github
10 дней назад
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
EPSS
Процентиль: 44%
0.0055
Низкий
8.8 High
CVSS3
Дефекты
CWE-130