Buffer Overflow Vulnerability in PPP by FreeBSD
CVE-2026-58095

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-58095?

A vulnerability exists in the FreeBSD Point-to-Point Protocol (PPP) where the mp_Enddisc() function improperly calculates the length of endpoint discriminator addresses. This flaw can lead to a buffer overflow, enabling a malicious PPP peer to crash the ppp(8) process or potentially execute arbitrary code with root privileges, posing significant security risks.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert Morris
Décio Brandão (0xDBJ)
Joshua Rogers
Reo Shiseki
.