PT-2026-95455 · Pppd · Pppd

CVE-2026-75883

·

Published

2026-09-17

·

Updated

2026-09-18

CVSS v3.1

6.8

Medium

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions pppd (affected versions not specified)
Description An issue exists in the peap response() function where a response to a PEAP Request packet is formatted by copying a TLS record of up to 16384 bytes into the fixed global buffer outpacket buf. This occurs without verifying available space or implementing outgoing PEAP fragmentation. Consequently, a process connecting to a server requesting PEAP authentication can be induced to corrupt global static data following the outpacket buf array, potentially leading to incorrect behavior or a system crash.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-103302
CVE-2026-75883
GHSA-RWR9-4VX8-VC35
OPENSUSE-SU-2026:11802-1

Affected Products

Pppd