CVE-2026-58095: Freebsd

High severity, CVSS 8.8. EPSS: 0.6% chance of exploitation in the next 30 days.

mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a global result buffer. A malicious PPP peer can crash ppp(8) or potentially execute arbitrary code as root.

Affected products

  • Freebsd Freebsd: version 14.4 only; version 15.0 only; version 15.1 only

Published 2026-08-26. Last modified 2026-09-10.