LcpDecodeConfig() 未对接收到的端点判别器(endpoint discriminator)选项的长度进行验证,以确保其满足 RFC 1717 规定的最小长度要求。过小的选项会引发越界写操作。 恶意 PPP 对等体可利用 CVE-2026-58095 和 CVE-2026-58096 漏洞导致 ppp(8) 进程崩溃,甚至可能以 root 权限执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58089 | hwpmc fails to detach PMCs during exec credential transitions | |
| CVE-2026-58090 | Use-after-free in unix SOCK_STREAM message handling | |
| CVE-2026-58091 | Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl | |
| CVE-2026-58092 | Unauthorized credential switching | |
| CVE-2026-58095 | ppp(8): incorrect length calculation in mp_Enddisc() | |
| CVE-2026-58097 | ppp(8): missing length validation in mp_SetEnddisc() | |
| CVE-2026-58093 | Kernel use-after-free via tty ioctls | |
| CVE-2026-58094 | TOCTOU race in POSIX shared memory large page configuration |
No comments yet