← Back

CVE-2026-58095

nvd nist
Published: Aug 26, 2026Modified: Sep 10, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root.

Affected (22)

Products: Freebsd: Freebsd
1 product
Freebsd
Configuration A
22 vulnerable
Vulnerable SoftwareAffected Versions
Freebsd
Version 14.4 p1
Version 14.4 p2
Version 14.4 p3
Version 14.4 p4
Version 14.4 p5
Version 14.4 p6
Version 14.4 p7
Version 14.4 p8
Version 15.0 p10
Version 15.0 p11
Version 15.0 p12
Version 15.0 p1
Version 15.0 p2
Version 15.0 p3
Version 15.0 p4
Version 15.0 p5
Version 15.0 p6
Version 15.0 p7
Version 15.0 p8
Version 15.0 p9
Version 15.1 p1
Version 15.1 p2

References (1)

Timeline

No history available yet.