logo

FreeRADIUS Security Patches Fix Critical Buffer Overflow Vulnerabilities

ID: 50d41d04-4594-50cd-bd5a-917af9368356

STIX ID: report--50d41d04-4594-50cd-bd5a-917af9368356

Feed Name: securityonline.info

Threat Score
70/100

Date Published: 2026-06-05

Date Updated: 2026-06-05

Author: Do Son

...
...

This advisory warns of severe unauthenticated buffer-overflow flaws in the widely deployed FreeRADIUS server—an attacker can send crafted UDP packets (e.g., a long NAS-Filter-Rule attribute) to crash the service before authentication checks, and multiple overflows affect EAP-MSCHAPv2, EAP-MD5 and TEAP. The maintainers withheld exploit details due to automated attack/tooling risks and urge immediate patching to FreeRADIUS 3.0.28 or 3.2.9 and validation of authentication environments.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.