7-Year-Old OpenBSD Security Flaw Exposes Systems to Full PAP Authentication Bypass
ID: 7086a7d0-a27a-5aca-94cf-31336d45765d
STIX ID: report--7086a7d0-a27a-5aca-94cf-31336d45765d
Feed Name: GBHackers
### Executive Summary A critical authentication bypass and kernel heap over-read were found in OpenBSD's PPP PAP handler (sppp_pap_input): by supplying zero-length PAP credentials an attacker can bypass PAP authentication and, when lengths exceed buffer sizes, trigger a heap over-read exposing kernel memory. The issue is remotely exploitable via PPPoE (attacker on the same broadcast domain acting as a rogue access concentrator), a PoC was demonstrated on OpenBSD 7.6, and a June 2026 patch enforces strict length checks to remediate both problems; affected organizations should apply the update and limit exposure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
