logo

7-Year-Old OpenBSD Security Flaw Exposes Systems to Full PAP Authentication Bypass

ID: 7086a7d0-a27a-5aca-94cf-31336d45765d

STIX ID: report--7086a7d0-a27a-5aca-94cf-31336d45765d

Feed Name: GBHackers

Threat Score
70/100

Date Published: 2026-06-17

Date Updated: 2026-06-17

Author: Divya

...
...

### Executive Summary A critical authentication bypass and kernel heap over-read were found in OpenBSD's PPP PAP handler (sppp_pap_input): by supplying zero-length PAP credentials an attacker can bypass PAP authentication and, when lengths exceed buffer sizes, trigger a heap over-read exposing kernel memory. The issue is remotely exploitable via PPPoE (attacker on the same broadcast domain acting as a rogue access concentrator), a PoC was demonstrated on OpenBSD 7.6, and a June 2026 patch enforces strict length checks to remediate both problems; affected organizations should apply the update and limit exposure.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.