Out-of-bounds write in PPP - CVE-2026-85495
Published: September 19, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause memory corruption.
The vulnerability exists due to an out-of-bounds write in pppd's lcp_reqci() LCP Configure-NAK construction when processing an LCP Configure-Request containing repeated PAP AUTHTYPE options. A remote attacker can send a crafted pre-authentication Configure-Request to cause memory corruption.
The issue is triggered when pppd is configured to refuse PAP and EAP while requiring CHAP.