Impact
The vulnerability is a buffer overflow in the PPP daemon’s peap_response() function, which copies up to 16384 bytes of a TLS record into a global buffer without bounds checking or PEAP fragmentation support. This flaw can corrupt static data beyond the buffer, potentially causing crashes or incorrect behavior. The weakness is identified as a classic buffer copy without size validation (CWE‑122).
Affected Systems
Affects the PPP Project’s PPP daemon (pppd), a widely used PPP implementation. No specific patch release or versioning information is provided in the advisory, so all installations of pppd that enable PEAP authentication are potentially vulnerable.
Risk and Exploitability
The CVSS base score of 6.8 indicates moderate severity and the vulnerability is not listed in the CISA KEV catalog. The EPSS score is < 1%, showing a very low likelihood of exploitation. The flaw can be triggered by a remote PEAP‑capable authentication server simply by initiating a PEAP session, which may lead to denial of service due to corruption of global static data. The likely attack vector is remote via PEAP authentication.
OpenCVE Enrichment
Debian DLA
Debian DSA