Heap-based buffer overflow in FreeBSD - CVE-2026-58095

 

Heap-based buffer overflow in FreeBSD - CVE-2026-58095

Published: August 26, 2026


Vulnerability identifier: #VU145744
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-58095
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to a buffer overflow in mp_Enddisc() when processing a received endpoint discriminator option. A remote attacker can send a specially crafted endpoint discriminator option to execute arbitrary code.

The issue can also crash ppp(8). Exploitation occurs in the Multilink PPP endpoint discriminator handling path.


Affected software

FreeBSD

How to mitigate CVE-2026-58095

Install security update from vendor's website.


External References

Related Security Bulletins