Executive brief
FreeBSD's ppp(8) is a dial-up networking utility installed with elevated (root) privileges. A local user with network group access can trigger a buffer overflow in the mp_SetEnddisc() function by supplying a specially crafted endpoint discriminator value, potentially crashing the service or executing arbitrary code with root privileges.
Technical details
CVE-2026-58097 is a stack-based buffer overflow in the mp_SetEnddisc() function of FreeBSD's ppp(8) daemon. The vulnerability occurs because the function copies a user-supplied PSN (Private Switched Network) endpoint discriminator value without validating its length against the destination buffer. The attack vector is local and requires the attacker to belong to the "network" group to invoke the ppp(8) command interface. Successful exploitation allows an attacker to crash ppp(8) or execute arbitrary code with root privileges. Patches were applied to stable/15, releng/15.1, releng/15.0, stable/14, and releng/14.4 branches as of August 24-25, 2026.
Affected products
- FreeBSD FreeBSD All supported versions up to and including 15.0, 14.4
Timeline
- 2026-08-25: disclosed
- 2026-08-24: patched: patches applied to stable/15, releng/15.1, releng/15.0, stable/14, and releng/14.4