<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T18:15:18.739314+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/alsa-2023:2166</id>
    <title>ALSA-2023:2166 — Moderate: freeradius security and bug fix update</title>
    <updated>2026-10-03T18:15:18.773735+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> AlmaLinux:9: freeradius, AlmaLinux:9: freeradius-devel, AlmaLinux:9: freeradius-doc, AlmaLinux:9: freeradius-krb5, AlmaLinux:9: freeradius-ldap, AlmaLinux:9: freeradius-mysql, AlmaLinux:9: freeradius-perl, AlmaLinux:9: freeradius-postgresql, AlmaLinux:9: freeradius-rest, AlmaLinux:9: freeradius-sqlite and 3 more</p>
<p>FreeRADIUS is a high-performance and highly configurable free Remote Authentication Dial In User Service (RADIUS) server, designed to allow centralized authentication and authorization for a network.</p>
<p>Security Fix(es):</p>
<p>* freeradius: Information leakage in EAP-PWD (CVE-2022-41859)
* freeradius: Crash on unknown option in EAP-SIM (CVE-2022-41860)
* freeradius: Crash on invalid abinary data (CVE-2022-41861)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the AlmaLinux Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/alsa-2023:2166"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-257689</id>
    <title>EUVD-2026-257689</title>
    <updated>2026-10-03T18:15:18.773830+00:00</updated>
    <content>EUVD-2026-257689</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-257689"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2022-41859</id>
    <title>fkie_cve-2022-41859</title>
    <updated>2026-10-03T18:15:18.773849+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2022-41859"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cmvm-c7qf-pmc5</id>
    <title>GHSA-cmvm-c7qf-pmc5</title>
    <updated>2026-10-03T18:15:18.773873+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cmvm-c7qf-pmc5"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2022-41859</id>
    <title>gsd-2022-41859</title>
    <updated>2026-10-03T18:15:18.773887+00:00</updated>
    <content>gsd-2022-41859</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2022-41859"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/oesa-2023-1953</id>
    <title>OESA-2023-1953 — freeradius security update</title>
    <updated>2026-10-03T18:15:18.773898+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> openEuler:20.03-LTS-SP1: freeradius</p>
<p>Remote Authentication Dial-In User Service (RADIUS) is a networking protocol that provides centralized Authentication, Authorization, and Accounting (AAA or Triple A) management for users who connect and use a network service.

Security Fix(es):

In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.(CVE-2022-41859)</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/oesa-2023-1953"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/opensuse-su-2024:13386-1</id>
    <title>openSUSE-SU-2024:13386-1 — freeradius-server-3.2.3-2.1 on GA media</title>
    <updated>2026-10-03T18:15:18.773920+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>freeradius-server-3.2.3-2.1 on GA media</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/opensuse-su-2024:13386-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rlsa-2023:2870</id>
    <title>RLSA-2023:2870 — Moderate: freeradius:3.0 security update</title>
    <updated>2026-10-03T18:15:18.773939+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Rocky Linux:8: freeradius</p>
<p>FreeRADIUS is a high-performance and highly configurable free Remote Authentication Dial In User Service (RADIUS) server, designed to allow centralized authentication and authorization for a network.</p>
<p>Security Fix(es):</p>
<p>* freeradius: Information leakage in EAP-PWD (CVE-2022-41859)</p>
<p>* freeradius: Crash on unknown option in EAP-SIM (CVE-2022-41860)</p>
<p>* freeradius: Crash on invalid abinary data (CVE-2022-41861)</p>
<p>For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.</p>
<p>Additional Changes:</p>
<p>For detailed information on changes in this release, see the Rocky Linux 8.8 Release Notes linked from the References section.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rlsa-2023:2870"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-su-2022:4620-1</id>
    <title>SUSE-SU-2022:4620-1 — Security update for freeradius-server</title>
    <updated>2026-10-03T18:15:18.773965+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for freeradius-server</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-su-2022:4620-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41859</id>
    <title>UBUNTU-CVE-2022-41859</title>
    <updated>2026-10-03T18:15:18.773983+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: freeradius, Ubuntu:20.04:LTS: freeradius</p>
<p>In freeradius, the EAP-PWD function compute_password_element() leaks information about the password which allows an attacker to substantially reduce the size of an offline dictionary attack.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2022-41859"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2411</id>
    <title>WID-SEC-W-2022-2411 — FreeRADIUS: Mehrere Schwachstellen</title>
    <updated>2026-10-03T18:15:18.774002+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in FreeRADIUS ausnutzen, um Informationen offenzulegen oder einen Denial of Service Zustand herbeizuführen.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/wid-sec-w-2022-2411"/>
  </entry>
</feed>
