Improper access control in PPP - #VU151451
Published: September 19, 2026
Vulnerability details
The vulnerability allows a local user to disclose sensitive information.
The vulnerability exists due to improper access control in pppd EAP-TLS and EAP-PEAP file and directory command-line options when processing user-specified file or directory paths. A local user can supply arbitrary paths through the ca, capath, crl-dir, crl, cert, key, or pkcs12 options to disclose sensitive information.
Exploitation requires pppd to be installed setuid-root and may disclose correctly formatted certificate or key material to the peer or influence data sent to the peer.