Skip to content
CVSS 9.8 · CRITICAL

CVE-2026-58096RCE como root en el demonio PPP (ppp8)

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.

Ver en NVD

Análisis

A critical vulnerability in the PPP daemon (ppp8) allows a malicious peer to execute arbitrary code with root privileges via crafted LCP configuration options. This impacts any Linux or BSD system utilizing PPP for networking, including certain VPN and point-to-point configurations.

Roles relevantes

LinuxciberseguridadBackendC

Severidad

Puntaje: 9.8(CRITICAL)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV: NETWORK
AC: LOW
PR: NONE
UI: NONE
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Tipo de falla (CWE): CWE-130CWE-787

EPSS

Probabilidad de explotación (próx. 30 días): 0.0029 (0.3%)
Percentil: 20.5%
EPSS: 2026-08-26

Descripción técnica

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.

Publicada: 26/8/2026, 6:16:26
Última modificación: 27/8/2026, 4:16:44

Referencias

InicioEventosBlogRecursosCursosEquipo