Stack-based buffer overflow in PPP - #VU151449
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a stack-based buffer overflow in the radius plugin's stack arrays used to format outgoing RADIUS packets when formatting an outgoing RADIUS packet after processing multiple avpair command-line options. A local user can supply numerous avpair command-line options to escalate privileges.
Exploitation requires pppd to be installed setuid-root and a file under /etc/ppp/peers to enable loading radius.so for an unprivileged user.