SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-58095

HIGH · CVSS 8.8 EPSS 0.56%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

A vulnerability in the mp_Enddisc() function allows a malicious PPP peer to exploit incorrect length calculations, leading to a buffer overflow in the global result buffer. This can result in the crash of the ppp(8) service or potentially enable arbitrary code execution with root privileges. Organizations utilizing affected PPP implementations should prioritize patching this critical vulnerability to mitigate severe security risks.

CVE
CVE-2026-58095
Severity
HIGH
CVSS
8.8
EPSS
0.56%

Original NVD Description

mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root.

Related CVEs

Other vulnerabilities affecting the same vendor(s)