Back

MEDIUM

PPPD buffer overflow in PEAP response code

Published Sep 18, 2026

Description

The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf without checking the available space and without implementing outgoing PEAP fragmentation. Thus a pppd process connecting to a server which requests PEAP authentication can be induced to corrupt global static data following the outpacket_buf array, most likely causing incorrect behavior or a crash.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner redhat
Published Sep 18, 2026
Updated Sep 22, 2026
Reserved Aug 18, 2026

CISA Vulnrichment

Updated Sep 22, 2026

NVD

Status Awaiting Analysis
Modified Sep 18, 2026

Red Hat

No data

ENISA EUVD

Assigner redhat
Published Sep 18, 2026
Updated Sep 22, 2026

GitHub

No data