Buffer Overflow Vulnerability in FreeBSD PPP Command Interface
CVE-2026-58097

Currently unrated

Key Information:

Vendor

FreeBSD

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-58097?

The vulnerability arises in the mp_SetEnddisc() function, which improperly handles user-supplied PSN endpoint values, leading to a buffer overflow. This flaw can be exploited by local users who have access to the PPP command interface, potentially allowing them to crash the service or execute arbitrary code with root privileges. System administrators should ensure they apply the latest patches and monitor their environments to mitigate the associated risks.

Affected Version(s)

FreeBSD 15.1-RELEASE

FreeBSD 15.0-RELEASE

FreeBSD 14.4-RELEASE

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert Morris
Décio Brandão (0xDBJ)
Joshua Rogers
Reo Shiseki
.