Heap-based buffer overflow in PPP - #VU151448
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a heap-based buffer overflow in the radius plugin's heap object used to store AVP values when processing an avpair command-line option with a very long value. A local user can supply an avpair option containing a very long value to escalate privileges.
Exploitation requires pppd to be installed setuid-root and a file under /etc/ppp/peers to enable loading radius.so for an unprivileged user.