Executive brief
pppd is a daemon used to establish PPP network connections, commonly for VPN and dial-up access. When connecting to a server that requests PEAP authentication, pppd can be forced to write up to 16KB of data into a fixed-size buffer without bounds checking, corrupting nearby memory and causing the process to crash or behave incorrectly. If pppd is installed with root privileges on a system, an attacker could potentially exploit this for privilege escalation.
Technical details
A buffer overflow exists in the peap_response() function in pppd versions 2.5.0 through 2.5.3, where TLS records up to 16384 bytes are copied into a fixed global buffer (outpacket_buf) without verifying available space or implementing PEAP fragmentation. The vulnerability is reachable when pppd is configured with PEAP authentication and a remote PEAP server is the attack source. While memory corruption and denial of service are confirmed, reliable code execution exploitation has not been demonstrated.
Affected products
- ppp-project pppd 2.5.0 through 2.5.3
Timeline
- 2026-08-21: disclosed: GitHub security advisory GHSA-rwr9-4vx8-vc35 published
- 2026-09-18: other: CVE-2026-75883 assigned
- 2026: patched: Fixed in pppd 2.5.4