SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-58097

HIGH · CVSS 7.8 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-08-26 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The vulnerability arises from the mp_SetEnddisc() function, which improperly handles user-supplied PSN endpoint values without validating their length, leading to a buffer overflow in the ppp(8) command interface. This flaw allows a local user to crash the ppp(8) service or potentially execute arbitrary code with root privileges. System administrators and security teams managing environments that utilize the ppp(8) command interface should prioritize addressing this vulnerability to mitigate the risk of unauthorized access and system instability.

CVE
CVE-2026-58097
Severity
HIGH
CVSS
7.8
EPSS
0.22%

Original NVD Description

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.

Related CVEs

Other vulnerabilities affecting the same vendor(s)