SB2026082160 - Multiple vulnerabilities in PPP
Published: August 21, 2026 Updated: September 19, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 11 vulnerabilities.
1) Out-of-bounds write (CVE-ID: CVE-2026-75883)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 8.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to corrupt memory.
The vulnerability exists due to out-of-bounds write in the peap_response() code path when formatting a response to a PEAP Request packet. A remote attacker can send a PEAP authentication request that causes a TLS record to be copied into a fixed global buffer without sufficient bounds checking to corrupt memory.
The pppd process must be configured to agree to PEAP authentication, such as when the ca option or the capath option is supplied. Each pppd instance communicates with a single remote PPP peer, so a crash denies service only to that peer.
2) Out-of-bounds write (CVE-ID: N/A)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 7.2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to out-of-bounds write in the radius plugin's serv->name[] and serv->port[] arrays when processing a radius plugin configuration file containing more than eight authserver or acctserver entries. A local user can cause processing of a crafted radius plugin configuration file to escalate privileges.
Exploitation requires pppd to be installed setuid-root and a file under /etc/ppp/peers to enable loading radius.so for an unprivileged user.
3) Stack-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-121 - Stack-based buffer overflow
CVSSv4: 7.2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a stack-based buffer overflow in the radius plugin's stack arrays used to format outgoing RADIUS packets when formatting an outgoing RADIUS packet after processing multiple avpair command-line options. A local user can supply numerous avpair command-line options to escalate privileges.
Exploitation requires pppd to be installed setuid-root and a file under /etc/ppp/peers to enable loading radius.so for an unprivileged user.
4) Heap-based buffer overflow (CVE-ID: N/A)
CWE-ID: CWE-122 - Heap-based Buffer Overflow
CVSSv4: 7.2 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in the radius plugin's heap object used to store AVP values when processing an avpair command-line option with a very long value. A local user can supply an avpair option containing a very long value to escalate privileges.
Exploitation requires pppd to be installed setuid-root and a file under /etc/ppp/peers to enable loading radius.so for an unprivileged user.
5) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 5.7 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to improper access control in the PPPD radius plugin when processing the radius-config-file command-line option. A remote attacker can specify an arbitrary configuration file path to disclose portions of the file through parse error messages.
Exploitation requires pppd to be installed setuid-root and a preconfigured peer file that loads the radius plugin.
6) Improper access control (CVE-ID: N/A)
CWE-ID: CWE-284 - Improper Access Control
CVSSv4: 6.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access control in pppd EAP-TLS and EAP-PEAP file and directory command-line options when processing user-specified file or directory paths. A local user can supply arbitrary paths through the ca, capath, crl-dir, crl, cert, key, or pkcs12 options to disclose sensitive information.
Exploitation requires pppd to be installed setuid-root and may disclose correctly formatted certificate or key material to the peer or influence data sent to the peer.
7) Out-of-bounds read (CVE-ID: N/A)
CWE-ID: CWE-125 - Out-of-bounds read
CVSSv4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to disclose sensitive information.
The vulnerability exists due to an out-of-bounds read in the chapms_make_response and chapms2_make_response functions in pppd/chap_ms.c when handling a CHAP challenge with an undersized Challenge-Value-Size field. A remote attacker can send a specially crafted CHAP challenge to disclose sensitive information.
MS-CHAP or MS-CHAPv2 support must be enabled, and exploitation requires control of or a man-in-the-middle position for the PPP server.
8) Use-after-free (CVE-ID: N/A)
CWE-ID: CWE-416 - Use After Free
CVSSv4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to use-after-free in the pppd EAP-TLS authentication handling when processing an extra EAP-TLS Ack packet after authentication completes. A remote user can send an extra EAP-TLS Ack packet to cause a denial of service.
Exploitation requires a certificate signed by a CA recognized by the local pppd and successful EAP-TLS authentication.
9) Input validation error (CVE-ID: N/A)
CWE-ID: CWE-20 - Improper input validation
CVSSv4: 5.3 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to inject routes into the pppd host.
The vulnerability exists due to improper input validation in the dhcpv6relay plugin when processing DHCPv6 frames received from a DHCPv6 client. A remote attacker can send crafted DHCPv6 frames to inject routes into the pppd host.
Only deployments where the local pppd provides IPv6 connectivity to the peer are affected.
10) Out-of-bounds write (CVE-ID: CVE-2026-85495)
CWE-ID: CWE-787 - Out-of-bounds write
CVSSv4: 2.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in pppd's lcp_reqci() LCP Configure-NAK construction when processing an LCP Configure-Request containing repeated PAP AUTHTYPE options. A remote attacker can send a crafted pre-authentication Configure-Request to cause memory corruption.
The issue is triggered when pppd is configured to refuse PAP and EAP while requiring CHAP.
11) Integer overflow (CVE-ID: N/A)
CWE-ID: CWE-190 - Integer overflow
CVSSv4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an integer underflow during EAP-PEAP Start packet handling in pppd when processing a second EAP-PEAP Start packet with a different identifier. A remote attacker can send a crafted second EAP-PEAP Start packet to cause a denial of service.
The local pppd instance must be configured to authenticate itself using PEAP and have a CA certificate configured.
Remediation
Install update from vendor's website.
References
- https://github.com/ppp-project/ppp/security/advisories/GHSA-rwr9-4vx8-vc35
- https://github.com/ppp-project/ppp/security/advisories/GHSA-626q-hc9r-2crc
- https://github.com/ppp-project/ppp/security/advisories/GHSA-gh98-jhjg-3hcm
- https://github.com/ppp-project/ppp/security/advisories/GHSA-3v58-8x3r-rc9w
- https://github.com/ppp-project/ppp/security/advisories/GHSA-j686-vmph-4m7c
- https://github.com/ppp-project/ppp/security/advisories/GHSA-cgh4-298h-6g7q
- https://github.com/ppp-project/ppp/security/advisories/GHSA-qph9-x4ch-c8c5
- https://github.com/ppp-project/ppp/commit/b9ab9cf22aba
- https://github.com/ppp-project/ppp/security/advisories/GHSA-frhv-j822-2pvx
- https://github.com/ppp-project/ppp/security/advisories/GHSA-p66j-h8pv-g4h9