without checking the available space and without implementing outgoing
PEAP fragmentation. Thus a pppd process connecting to a server which
requests PEAP authentication can be induced to corrupt global static
data following the outpacket_buf array, most likely causing incorrect behavior or a crash.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-6498-1 | network-manager-l2tp security update |
Fri, 18 Sep 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementing outgoing PEAP fragmentation. Thus a pppd process connecting to a server which requests PEAP authentication can be induced to corrupt global static data following the outpacket_buf array, most likely causing incorrect behavior or a crash. | |
| Title | PPPD buffer overflow in PEAP response code | |
| Weaknesses | CWE-122 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-09-18T15:29:07.702Z
Reserved: 2026-08-18T13:09:30.492Z
Link: CVE-2026-75883
No data.
Status : Awaiting Analysis
Published: 2026-09-18T16:17:09.167
Modified: 2026-09-18T19:06:08.407
Link: CVE-2026-75883
No data.
OpenCVE Enrichment
No data.
-
CWE-122
Heap-based Buffer Overflow
Debian DSA