Heap-based buffer overflow in FreeBSD - CVE-2026-58095
Published: August 26, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a buffer overflow in mp_Enddisc() when processing a received endpoint discriminator option. A remote attacker can send a specially crafted endpoint discriminator option to execute arbitrary code.
The issue can also crash ppp(8). Exploitation occurs in the Multilink PPP endpoint discriminator handling path.