Executive brief
FreeBSD's ppp(8) is a network utility for establishing Point-to-Point Protocol connections, commonly used for dial-up and serial links. A malicious remote peer can send specially crafted endpoint discriminator options that cause a buffer overflow in the ppp daemon, crashing the service or potentially executing arbitrary code with root privileges.
Technical details
The mp_Enddisc() function in ppp(8) uses incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. The vulnerability is a classic buffer overflow triggered via network input from a malicious PPP peer. Since ppp(8) runs as setuid root (though restricted to the "network" group), successful exploitation grants root code execution. No user authentication or interaction is required; a remote attacker needs only to establish a PPP connection. Patches are available for all supported FreeBSD versions (14.4, 15.0, 15.1).
Affected products
- FreeBSD FreeBSD All supported versions (14.4 before 2026-08-25, 15.0 before 2026-08-25, 15.1 before 2026-08-25)
Timeline
- 2026-08-25: disclosed
- 2026-08-25: patched