Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-58096

Опубликовано: 26 авг. 2026
Источник: nvd
CVSS3: 8.8
EPSS Низкий

Описание

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write.

A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.

EPSS

Процентиль: 44%
0.0055
Низкий

8.8 High

CVSS3

Дефекты

CWE-130

Связанные уязвимости

CVSS3: 9.8
github
10 дней назад

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.

EPSS

Процентиль: 44%
0.0055
Низкий

8.8 High

CVSS3

Дефекты

CWE-130