{"id":"CVE-2026-75883","published":"2026-09-18T16:17:09.167","lastModified":"2026-09-22T15:17:13.797","description":"The code in pppd that formats a response to a PEAP Request packet in peap_response() copies an entire TLS record of up to 16384 bytes into the fixed global buffer outpacket_buf\n without checking the available space and without implementing outgoing \nPEAP fragmentation. Thus a pppd process connecting to a server which \nrequests PEAP authentication can be induced to corrupt global static \ndata following the outpacket_buf array, most likely causing incorrect behavior or a crash.","cvssScore":6.8,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N","cwes":["CWE-122"],"vendors":[],"products":[],"references":[{"url":"https://github.com/ppp-project/ppp/security/advisories/GHSA-rwr9-4vx8-vc35","tags":[]}],"exploitRefs":[{"url":"https://github.com/ppp-project/ppp/security/advisories/GHSA-rwr9-4vx8-vc35","tags":[]}],"hasPoc":true,"ai":null}