PT-2026-99964 · Azure Linux · Ppp

Published

2026-09-18

·

Updated

2026-09-18

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The code in pppd that formats a response to a PEAP Request packet in peap response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket buf without checking the available space and without implementing outgoing PEAP fragmentation. Thus a pppd process connecting to a server which requests PEAP authentication can be induced to corrupt global static data following the outpacket buf array, most likely causing incorrect behavior or a crash.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

AZL-103302

Affected Products

Ppp