{"id":"CVE-2026-75883","title":"The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf\n without checking the available space and without implementi…","summary":"The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf\n without checking the available space and without implementi…","severity":"medium","cvss":6.8,"cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwe":["CWE-122"],"vendor":"PPP Project","product":"ppp","affected":["ppp <= 2.5.0"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T19:06:08.407","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75883","references":[{"url":"https://github.com/ppp-project/ppp/security/advisories/GHSA-rwr9-4vx8-vc35","label":"secalert@redhat.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-18T15:44:31.582Z","epss":0.00255,"epssPercentile":0.17428,"slug":"CVE-2026-75883","body":"## Overview\n\nThe code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf\n without checking the available space and without implementing outgoing \nPEAP fragmentation. Thus a pppd process connecting to a server which \nrequests PEAP authentication can be induced to corrupt global static \ndata following the outpacket_buf array, most likely causing incorrect behavior or a crash.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":37,"depthScoreParts":{"impact":37.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}