mp_SetEnddisc() 函数在未进行长度验证的情况下复制了用户提供的 PSN(PPP Stream Number)端点值,从而导致通过 ppp(8) 命令接口发生缓冲区溢出。 拥有 ppp(8) 命令接口访问权限的本地用户可导致 ppp(8) 崩溃,并可能以 root 权限执行任意代码。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-58090 | Use-after-free in unix SOCK_STREAM message handling | |
| CVE-2026-58091 | Kernel use-after-free via the SNDCTL_DSP_SYNCSTART ioctl | |
| CVE-2026-58092 | Unauthorized credential switching | |
| CVE-2026-58089 | hwpmc fails to detach PMCs during exec credential transitions | |
| CVE-2026-58095 | ppp(8): incorrect length calculation in mp_Enddisc() | |
| CVE-2026-58093 | Kernel use-after-free via tty ioctls | |
| CVE-2026-58096 | ppp(8): missing length validation in LcpDecodeConfig() | |
| CVE-2026-58094 | TOCTOU race in POSIX shared memory large page configuration |
No comments yet