VYPR
Critical severity9.8NVD Advisory· Published Feb 14, 2022· Updated Jun 17, 2026

CVE-2022-24704

CVE-2022-24704

Description

The rad_packet_recv function in opt/src/accel-pppd/radius/packet.c suffers from a buffer overflow vulnerability, whereby user input len is copied into a fixed buffer &attr->val.integer without any bound checks. If the client connects to the server and sends a large radius packet, a buffer overflow vulnerability will be triggered.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • xebd/ACCEL-PPP2 versions
    cpe:2.3:a:accel-ppp:accel-ppp:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:accel-ppp:accel-ppp:*:*:*:*:*:*:*:*range: <=1.12.0
    • (no CPE)
  • https://accel-ppp.org//Accel-PPPv5
    Range: 1.12

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.