logo

27-Year-Old OpenBSD Vulnerability Allows Attackers to Bypass PAP Authentication Entirely

ID: a6bed0b9-4ade-5d69-8dee-bbf286be88a7

STIX ID: report--a6bed0b9-4ade-5d69-8dee-bbf286be88a7

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Abinaya

...
...

A 27-year-old logic flaw in OpenBSD's PPP PAP handler (sppp_pap_input) allows attackers to bypass PAP authentication by supplying attacker-controlled length fields (e.g., zero-length credentials) and can trigger kernel heap overreads when providing oversized lengths. The vulnerability is reachable via the PPPoE data path, a proof-of-concept shows full session establishment and traffic routing through a rogue PPPoE server, and a fix adding strict length checks was released promptly—organisations using OpenBSD with PPPoE/PAP should apply patches immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.