CVE-2026-58097: Freebsd
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.
Affected products
- Freebsd Freebsd: version 14.4 only; version 15.0 only; version 15.1 only
Published 2026-08-26. Last modified 2026-09-10.