CVE-2022-41859
The EAP-PWD function compute_password_element() leaks information
about the password which allows an attacker to substantially
reduce the size of an offline dictionary attack.
CVE-2022-41860
When an EAP-SIM supplicant sends an unknown SIM option, the server
will try to look that option up in the internal dictionaries. This
lookup will fail, but the SIM code will not check for that
failure. Instead, it will dereference a NULL pointer, and cause
the server to crash.
CVE-2022-41861
A malicious RADIUS client or home server can send a malformed
abinary attribute which can cause the server to crash. This crash
is not exploitable by end users. Only systems which are in the
RADIUS circle of trust can send these malformed attributes to a
server.
For Debian 11 bullseye, these problems have been fixed in version
3.0.21+dfsg-2.2+deb11u2.
We recommend that you upgrade your freeradius packages.
Get the latest Linux and open source security news straight to your inbox.