CVE-2026-58096
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersiz
CVSS
8.8
Alto
EPSS
0.3%
p21
KEV
—
Exploit Today
6
0-100
Publicado: 26 ago 2026 · Última mod.: 27 ago 2026 · CWE-130 · CWE-787
Sin historial EPSS suficiente todavía.
LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options would trigger an out-of-bounds write. A malicious PPP peer can exploit CVE-2026-58095 and CVE-2026-58096 to crash ppp(8) or potentially execute arbitrary code as root.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-580977.8 ALT18.8%
——6mp_SetEnddisc() copied a user-supplied PSN endpoint value without length validation, allowing a buffer overflow via the ppp(8) command interface.
A local user with access to the ppp(8) command interface can crash ppp(8) or potentially execute arbitrary code as root.15hCVE-2026-792408.8 ALT16.5%
——5Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)15hCVE-2026-791899.6 CRÍ16.5%
——5Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)15hCVE-2026-791889.6 CRÍ22.2%
——7Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)6hCVE-2026-791389.6 CRÍ16.5%
——5Out of bounds write in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)7hCVE-2026-791319.6 CRÍ22.2%
——7Out of bounds write in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: High)7h