Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-75883— PPPD buffer overflow in PEAP response code

Quick assessment

Affected
PPP Project ppp
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

中用于处理 PEAP 请求数据包响应的代码位于 函数。该函数会将最长为 16384 字节的完整 TLS 记录直接复制到全局固定大小的缓冲区 中,但并未检查缓冲区的可用空间,也未实现出站 PEAP 分片机制。因此,当 进程连接到一个要求进行 PEAP 认证服务器时,可能导致 数组之后的全局静态数据被破坏,从而最有可能引发异常行为或进程崩溃。

CVSS 6.8 · Medium EPSS 0.18% · P7

Affected Version Matrix 2

VendorProduct Version RangeStatus
PPP Project ppp ≤ 2.5.0 affected
2.5.4 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-75883

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
PPPD buffer overflow in PEAP response code
Source: CVE Program / CVE List V5
Vulnerability Description
The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementing outgoing PEAP fragmentation. Thus a pppd process connecting to a server which requests PEAP authentication can be induced to corrupt global static data following the outpacket_buf array, most likely causing incorrect behavior or a crash.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
堆缓冲区溢出
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
PPP Project ppp 0 ~ 2.5.0 -

II. Public POCs for CVE-2026-75883

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-75883

请登录查看更多情报信息。

Vendor Advisories for CVE-2026-75883 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-75883

No comments yet


Leave a comment