PT-2026-99964 · Azure Linux · Ppp
Published
2026-09-18
·
Updated
2026-09-18
None
No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
The code in pppd that formats a response to a PEAP Request packet in peap response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket buf
without checking the available space and without implementing outgoing
PEAP fragmentation. Thus a pppd process connecting to a server which
requests PEAP authentication can be induced to corrupt global static
data following the outpacket buf array, most likely causing incorrect behavior or a crash.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ppp