In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DLA |
DLA-3342-1 | freeradius security update |
Debian DLA |
DLA-4232-1 | freeradius security update |
EUVD |
EUVD-2022-45024 | In freeradius, when an EAP-SIM supplicant sends an unknown SIM option, the server will try to look that option up in the internal dictionaries. This lookup will fail, but the SIM code will not check for that failure. Instead, it will dereference a NULL pointer, and cause the server to crash. |
Ubuntu USN |
USN-5785-1 | FreeRADIUS vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 03 Nov 2025 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Mon, 03 Nov 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2025-11-03T19:27:38.875Z
Reserved: 2022-09-30T00:00:00.000Z
Link: CVE-2022-41860
Updated: 2025-11-03T19:27:38.875Z
Status : Modified
Published: 2023-01-17T18:15:11.387
Modified: 2025-11-03T20:15:57.650
Link: CVE-2022-41860
OpenCVE Enrichment
No data.
Debian DLA
EUVD
Ubuntu USN