Junglewise Threat Intelligence

CVE-2026-75883: pppd buffer overflow in PEAP response handling

CVE-2026-75883 · Severity: medium · CVSS 6.8 · Published 2026-09-18

Executive brief

pppd is a daemon used to establish PPP network connections, commonly for VPN and dial-up access. When connecting to a server that requests PEAP authentication, pppd can be forced to write up to 16KB of data into a fixed-size buffer without bounds checking, corrupting nearby memory and causing the process to crash or behave incorrectly. If pppd is installed with root privileges on a system, an attacker could potentially exploit this for privilege escalation.

Technical details

A buffer overflow exists in the peap_response() function in pppd versions 2.5.0 through 2.5.3, where TLS records up to 16384 bytes are copied into a fixed global buffer (outpacket_buf) without verifying available space or implementing PEAP fragmentation. The vulnerability is reachable when pppd is configured with PEAP authentication and a remote PEAP server is the attack source. While memory corruption and denial of service are confirmed, reliable code execution exploitation has not been demonstrated.

Affected products

  • ppp-project pppd 2.5.0 through 2.5.3

Timeline

  • 2026-08-21: disclosed: GitHub security advisory GHSA-rwr9-4vx8-vc35 published
  • 2026-09-18: other: CVE-2026-75883 assigned
  • 2026: patched: Fixed in pppd 2.5.4

References