Alerts This Week
Warning Icon 1 1,234
Alerts This Week
Warning Icon 1 1,234

Debian 11: DLA-4232-1 important: freeradius denial of service

debian lts
Calendar Grey June 26, 2025
Dist Debian Esm H88
Issues in freeradius security necessitate an immediate upgrade to safeguard networks and avert possible downtime.
Several security vulnerabilities have been discovered in freeradius, a highly configurable RADIUS server

Summary


CVE-2022-41859

The EAP-PWD function compute_password_element() leaks information
about the password which allows an attacker to substantially
reduce the size of an offline dictionary attack.

CVE-2022-41860

When an EAP-SIM supplicant sends an unknown SIM option, the server
will try to look that option up in the internal dictionaries. This
lookup will fail, but the SIM code will not check for that
failure. Instead, it will dereference a NULL pointer, and cause
the server to crash.

CVE-2022-41861

A malicious RADIUS client or home server can send a malformed
abinary attribute which can cause the server to crash. This crash
is not exploitable by end users. Only systems which are in the
RADIUS circle of trust can send these malformed attributes to a
server.

For Debian 11 bullseye, these problems have been fixed in version
3.0.21+dfsg-2.2+deb11u2.

We recommend that you upgrade your freeradius packages.

Read the Full Advisory


Severity
important
Lowest
Low
Medium
High
Critical

Package: freeradius
Version: 3.0.21+dfsg-2.2+deb11u2
CVE ID: CVE-2022-41859 CVE-2022-41860 CVE-2022-41861

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here