Junglewise Threat Intelligence

CVE-2026-55706: OpenBSD auth bypass and heap over-read in sppp_pap_input

CVE-2026-55706 · Severity: medium · CVSS 5.8 · Published 2026-06-17

Technologies: Openbsd. Vendors: OpenBSD.

Executive brief

A vulnerability in OpenBSD's networking stack allows an attacker to bypass password requirements when connecting via certain types of internet links (PPPoE). By sending specially crafted empty credentials, an attacker on the same local network can gain unauthorized access to the network link or trick the system into routing traffic through a malicious server. This flaw has existed in the system's code for 27 years and could lead to intercepted data or unauthorized network access.

Technical details

The sppp_pap_input function in OpenBSD's PPP implementation (sys/net/if_spppsubr.c) improperly validates the length of incoming Password Authentication Protocol (PAP) credentials. The code uses attacker-controlled length fields as the comparison length for bcmp() without verifying they match the actual stored credential length. An attacker can send zero-length name and password fields, causing bcmp() to return 0 (success) unconditionally, bypassing authentication. Additionally, providing a length larger than the stored credential causes a kernel heap over-read. The vulnerability is reachable via the PPPoE data path and requires the target to be configured as a PAP authenticator. A fix was committed on June 14, 2026, which implements exact-length checks before comparison.

Affected products

  • OpenBSD OpenBSD before commit 076e2b1 (including version 7.6)

Timeline

  • 1999-07-01: other: Vulnerable code imported into OpenBSD from FreeBSD
  • 2026-06-12: disclosed: Reported to OpenBSD by Argus
  • 2026-06-14: patched: Fix committed to OpenBSD source tree
  • 2026-06-17: advisory: CVE published

References

Related threats