CVE-2017-10986: High severity freeradius vulnerability

Published Jul 7, 2017
·
Updated

An FR-GV-303 issue in FreeRADIUS 3.x before 3.0.15 allows "DHCP - Infinite read in dhcpattr2vp()" and a denial of service.

Other sources

When decoding "string" options in an array, dhcpattr2vp() could be convinced to call memchr() with a length argument of -1. This could result in an over-read until the first zero octet was found, or a page fault occured.

The security impact is denial of service by any network device capable of sending DHCP packets to FreeRADIUS, which sends string options to the server in an option array.

Affected versions: 3.0.0 through 3.0.14, inclusive.

Red Hat

Affected Software

16 affected componentsFixes available
redhat/freeradius<3.0.15
3.0.15
FreeRADIUS freeradius=3.0.0
FreeRADIUS freeradius=3.0.1
FreeRADIUS freeradius=3.0.2
FreeRADIUS freeradius=3.0.3
FreeRADIUS freeradius=3.0.4
FreeRADIUS freeradius=3.0.5
FreeRADIUS freeradius=3.0.6
FreeRADIUS freeradius=3.0.7
FreeRADIUS freeradius=3.0.8
FreeRADIUS freeradius=3.0.9
FreeRADIUS freeradius=3.0.10
FreeRADIUS freeradius=3.0.11
FreeRADIUS freeradius=3.0.12
FreeRADIUS freeradius=3.0.13
FreeRADIUS freeradius=3.0.14

Event History

Jul 17, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description

Frequently Asked Questions

1

What is the severity of CVE-2017-10986?

CVE-2017-10986 is classified as a denial of service vulnerability in FreeRADIUS that can lead to service interruptions.

2

How do I fix CVE-2017-10986?

To fix CVE-2017-10986, upgrade FreeRADIUS to version 3.0.15 or later.

3

What software is affected by CVE-2017-10986?

CVE-2017-10986 affects FreeRADIUS versions prior to 3.0.15.

4

What type of vulnerability is CVE-2017-10986?

CVE-2017-10986 is a security vulnerability that allows for an infinite read within the DHCP attribute processing.

5

Can CVE-2017-10986 be exploited remotely?

Yes, CVE-2017-10986 can be exploited remotely, potentially allowing an attacker to cause a denial of service.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203