Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-14612

Опубликовано: 03 июл. 2026
Источник: redhat
CVSS3: 4.2
EPSS Низкий

Описание

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon.

Отчет

Red Hat rates this issue as Low impact. Although the flaw is reachable over the network once an external IdP is configured, exploitation is not straightforward: a successful attack would require an attacker to control, or be able to man-in-the-middle, the configured IdP endpoint and to supply an oversized device authorization response while a domain user is starting that OAuth2 login flow. We have not identified a path to arbitrary code execution, privilege escalation, or disclosure of Kerberos keys or other IdM secrets. The practical outcome is limited to instability or crash of the ipa-otpd service handling that authentication attempt.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10ipaFix deferred
Red Hat Enterprise Linux 6ipaOut of support scope
Red Hat Enterprise Linux 7ipaFix deferred
Red Hat Enterprise Linux 8idm:client/ipaFix deferred
Red Hat Enterprise Linux 8idm:DL1/ipaFix deferred
Red Hat Enterprise Linux 9ipaFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2496879freeipa: ipa: idm: freeipa: off-by-one buffer overflows in ipa-otpd oauth2.c during OAuth2 device authorization

EPSS

Процентиль: 4%
0.00142
Низкий

4.2 Medium

CVSS3

Связанные уязвимости

CVSS3: 4.2
ubuntu
около 2 месяцев назад

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon.

CVSS3: 4.2
nvd
около 2 месяцев назад

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon.

CVSS3: 4.2
debian
около 2 месяцев назад

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device a ...

CVSS3: 4.2
github
около 2 месяцев назад

Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon.

EPSS

Процентиль: 4%
0.00142
Низкий

4.2 Medium

CVSS3