CVE-2026-58096

Published Aug 26, 2026

Last updated 10 days ago

Overview

Description
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
Source
secteam@freebsd.org
NVD status
Analyzed
Products
freebsd

Risk scores

CVSS 3.1

Type
Secondary
Base score
8.8
Impact score
5.9
Exploitability score
2.8
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity
HIGH

Weaknesses

secteam@freebsd.org
CWE-130

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.