CVE-2018-11574: Canonical Ubuntu Linux
Critical severity, CVSS 9.8. EPSS: 1.9% chance of exploitation in the next 30 days.
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the affected eap.c and eap-tls.c files. Configurations that use the `refuse-app` option are unaffected.
Affected products
- Canonical Ubuntu Linux: version 14.04 only; version 16.04 only; version 18.04 only
- Point-To-Point Protocol Project Point-To-Point Protocol: before 2.4.9 (fixed in 2.4.9)
Published 2018-06-14. Last modified 2026-06-17.