Description
Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon.
Published: 2026-07-03
Score: 4.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Two off‑by‑one errors in the FreeIPA ipa‑otpd daemon’s OAuth2 device authorization handler can trigger an out‑of‑bounds memory access when the daemon processes an oversized response from a configured external OAuth2/OIDC Identity Provider. The overflow is a classic buffer overflow (CWE‑787) that allows an attacker to read or write a single byte past the end of a fixed‑size buffer, potentially crashing or causing a denial of service in the ipa‑otpd daemon. The most probable consequence is a limited denial of service that would disrupt the IPA device authorization service but does not expose application data or system privileges.

Affected Systems

FreeIPA installations running on Red Hat Enterprise Linux 6 through 10 that are configured with an external identity provider are affected. The vulnerable component is the ipa‑otpd daemon within those operating systems; the issue relies on a statically configured IdP and incoming OAuth2 device authorization requests.

Risk and Exploitability

The vulnerability carries a CVSS score of 4.2, indicating moderate severity. The EPSS score of < 1% shows a very low likelihood of exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires an attacker to control or intercept the external IdP endpoint and a user to initiate an OAuth2 device authorization flow, making the attack scenario moderately constrained. Given the limited impact and low likelihood, the overall risk is moderate, but monitoring for future patches is advised.

Generated by OpenCVE AI on July 21, 2026 at 09:48 UTC.

Remediation

Vendor Workaround

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.


OpenCVE Recommended Actions

  • Apply any forthcoming Red Hat patches for FreeIPA that address the off‑by‑one buffer overflow, following vendor release notes.
  • Restrict network access for the ipa‑otpd process so that only trusted infrastructure can communicate with the external IdP endpoint, limiting the attacker’s ability to supply a malicious response.
  • If the external IdP cannot be securely managed, remove or disable the IdP configuration to eliminate the vulnerable code path.

Generated by OpenCVE AI on July 21, 2026 at 09:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 07 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 04 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Low


Fri, 03 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon.
Title Freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during oauth2 device authorization
First Time appeared Redhat
Redhat enterprise Linux
Weaknesses CWE-787
CPEs cpe:/o:redhat:enterprise_linux:10
cpe:/o:redhat:enterprise_linux:6
cpe:/o:redhat:enterprise_linux:7
cpe:/o:redhat:enterprise_linux:8
cpe:/o:redhat:enterprise_linux:9
Vendors & Products Redhat
Redhat enterprise Linux
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L'}


Subscriptions

Redhat Enterprise Linux
cve-icon MITRE

Status: PUBLISHED

Assigner: redhat

Published:

Updated: 2026-07-07T02:16:43.353Z

Reserved: 2026-07-03T14:36:01.997Z

Link: CVE-2026-14612

cve-icon Vulnrichment

Updated: 2026-07-07T02:16:39.542Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Low

Publid Date: 2026-07-03T14:00:00Z

Links: CVE-2026-14612 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-21T10:00:04Z

Weaknesses