SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-58096

HIGH · CVSS 8.8 EPSS 0.56% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability in LcpDecodeConfig() allows for an out-of-bounds write due to insufficient validation of endpoint discriminator options, potentially leading to crashes or arbitrary code execution with root privileges. This critical flaw affects unspecified products using the PPP protocol, making it essential for organizations relying on PPP implementations to prioritize patching and mitigation efforts. Immediate action is recommended to prevent exploitation by malicious peers.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-58096
Severity
HIGH
CVSS
8.8
EPSS
0.56%

Original NVD Description

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.

Related CVEs

Other vulnerabilities affecting the same vendor(s)