Variable underflow exists in accel-ppp radius/packet.c when receiving a RADIUS vendor-specific attribute with length field is less than 2. It has an impact only when the attacker controls the RADIUS server, which can lead to arbitrary code execution.
{
"unresolved_ranges": [
{
"source": "CPE_RANGE",
"cpes": [
"cpe:2.3:a:accel-ppp:accel-ppp:*:*:*:*:*:*:*:*"
],
"vendor_product": "accel-ppp:accel-ppp",
"extracted_events": [
{
"fixed": "1.12.0-e9d369a"
}
]
}
]
}[
{
"digest": {
"length": 3593.0,
"function_hash": "218305480135744760965322474118285676607"
},
"signature_version": "v1",
"source": "https://github.com/accel-ppp/accel-ppp/commit/e9d369aa0054312b7633e964e9f7eb323f1f3d69",
"signature_type": "Function",
"target": {
"function": "rad_packet_recv",
"file": "accel-pppd/radius/packet.c"
},
"id": "CVE-2020-28194-28ac3858",
"deprecated": false
},
{
"digest": {
"threshold": 0.9,
"line_hashes": [
"53169831652962479236524189091079696734",
"193894202797788791053606579230416303418",
"56156999255468833464194175077938322916",
"108214281405374322627184477935854642973"
]
},
"signature_version": "v1",
"source": "https://github.com/accel-ppp/accel-ppp/commit/e9d369aa0054312b7633e964e9f7eb323f1f3d69",
"signature_type": "Line",
"target": {
"file": "accel-pppd/radius/packet.c"
},
"id": "CVE-2020-28194-2fff89dc",
"deprecated": false
}
]
"2026-07-09T11:24:10Z"
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2020-28194.json"