CVEFinder.io

CVE-2026-58097

⚠️ high
πŸ” Scan for this CVE
Summary

mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface. A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.

CVSS Score
7.8
High
EPSS Score
0.2
Exploit Probability
Published Date
2026-08-26
First Seen: 2026-08-28
πŸ“Š Relative Risk Intelligence

This CVE is Moderate Risk - more severe than 68.5% of all 360,673 vulnerabilities in our database.

#113,591
Above average severity
Severity Percentile
🎯 CISA SSVC Assessment Updated: Aug 26, 2026
πŸ” Exploitation Status
None
No known exploits
βš™οΈ Automatable
NO
Requires human interaction
πŸ’₯ Technical Impact
Total
Complete system compromise possible
πŸ† Discovered By
Robert Morris DΓ©cio BrandΓ£o (0xDBJ) Joshua Rogers Reo Shiseki
SSVC data provided by CISA
Last Modified 2026-09-10
CVSS Vector 3.1 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE IDs (Weakness Types)

πŸ“¦ Affected Products 3

πŸ”— References 1

πŸ”— Related CVEs 6

CVE ID Severity CVSS EPSS Summary Published
CVE-2026-58095 ⚠️ high 8.8 0.6 mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a... 2026-08-26
CVE-2026-58096 ⚠️ high 8.8 0.6 LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by... 2026-08-26
CVE-2026-49415 ⚠️ high 8.8 0.2 During execve(2) of a SUID binary, the new virtual address space is installed before the process credentials are updated... 2026-08-19
CVE-2026-49418 ⚠️ high 8.8 0.3 When msync(MS_INVALIDATE) is called on a mapping of an unmanaged device object, the physical pages in the mapping range ... 2026-08-19
CVE-2026-49419 ⚠️ high 8.8 0.3 When the JAIL_AT_DESC flag is specified, kern_jail_set() and kern_jail_get() released the reference to the caller's curr... 2026-08-19
CVE-2026-49420 ⚠️ high 8.8 0.3 The RTSP handler in libalias rewrote outgoing packets into a fixed-length stack buffer without checking whether the rewr... 2026-08-19
These CVEs affect the same products