CyberRota Analysis
AI-GeneratedThe vulnerability in LcpDecodeConfig() allows for an out-of-bounds write due to insufficient validation of endpoint discriminator options, potentially leading to crashes or arbitrary code execution with root privileges. This critical flaw affects unspecified products using the PPP protocol, making it essential for organizations relying on PPP implementations to prioritize patching and mitigation efforts. Immediate action is recommended to prevent exploitation by malicious peers.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
Related CVEs
Other vulnerabilities affecting the same vendor(s)