Integer overflow in PPP - #VU151452
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to an integer underflow during EAP-PEAP Start packet handling in pppd when processing a second EAP-PEAP Start packet with a different identifier. A remote attacker can send a crafted second EAP-PEAP Start packet to cause a denial of service.
The local pppd instance must be configured to authenticate itself using PEAP and have a CA certificate configured.