[From nobody Fri Jul 10 08:07:07 2026
Received: (at submit) by bugs.debian.org; 4 Jun 2026 06:03:09 +0000
X-Spam-Checker-Version: SpamAssassin 4.0.1-bugs.debian.org_2005_01_02
 (2024-03-25) on buxtehude.debian.org
X-Spam-Level: 
X-Spam-Status: No, score=-15.0 required=4.0 tests=BAYES_00,
 BODY_INCLUDES_PACKAGE,DKIM_SIGNED,DKIM_VALID,DKIM_VALID_AU,
 DKIM_VALID_EF,HAS_PACKAGE,RCVD_IN_DNSWL_LOW,SPF_HELO_PASS,SPF_PASS
 autolearn=ham autolearn_force=no
 version=4.0.1-bugs.debian.org_2005_01_02
X-Spam-Bayes: score:0.0000 Tokens: new, 45; hammy, 63; neutral, 25; spammy, 1.
 spammytokens:0.886-+--secret hammytokens:0.000-+--dfsg-1,
 0.000-+--dfsg1, 0.000-+--freeradius, 0.000-+--deb13u2,
 0.000-+--H*F:U*debian
Return-path: &lt;herwin@herwinw.nl&gt;
Received: from outbound8.mail.transip.nl ([136.144.136.8]:54340)
 by buxtehude.debian.org with esmtps
 (TLS1.3:ECDHE_X25519__RSA_PSS_RSAE_SHA256__AES_256_GCM:256)
 (Exim 4.96) (envelope-from &lt;herwin@herwinw.nl&gt;) id 1wV1AV-00Eozr-1r
 for submit@bugs.debian.org; Thu, 04 Jun 2026 06:03:09 +0000
Received: from submission11.mail.transip.nl (unknown [10.103.8.162])
 by outbound8.mail.transip.nl (Postfix) with ESMTP id 4gWDP64zGhzY76XT
 for &lt;submit@bugs.debian.org&gt;; Thu,  4 Jun 2026 07:57:30 +0200 (CEST)
Received: from herwinw.nl (unknown [IPv6:2a01:7c8:bb01:4d1::1])
 by submission11.mail.transip.nl (Postfix) with ESMTPSA id 4gWDP573w8z3R3nyt
 for &lt;submit@bugs.debian.org&gt;; Thu,  4 Jun 2026 07:57:29 +0200 (CEST)
Received: from herwin by herwinw.nl with local (Exim 4.98.2)
 (envelope-from &lt;herwin@herwinw.nl&gt;) id 1wV157-00000001oYj-3iU1
 for submit@bugs.debian.org; Thu, 04 Jun 2026 07:57:29 +0200
Date: Thu, 4 Jun 2026 07:57:29 +0200
From: Herwin Weststrate &lt;debian@herwinw.nl&gt;
To: submit@bugs.debian.org
Subject: Various security fixes in freeradius
Message-ID: &lt;aiETyT-vdd2Pirzx@herwinw.nl&gt;
MIME-Version: 1.0
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
X-Scanned-By: ClueGetter at submission11.mail.transip.nl
DKIM-Signature: v=1; a=rsa-sha256; q=dns/txt; c=relaxed/relaxed;
 s=transip-a; d=herwinw.nl; t=1780552650; h=from:subject:to:date:
 mime-version:content-type;
 bh=FzWMVA1dDZq+ZQhI04uuq3ik2zqSvvQwuRrmsy5hdk4=;
 b=B4pszOyhHlev/cmHwaKXaVHxktRJKXpMvrM+xP+/H3tgGPGhcCU5qyPh9U95uoAqyYuPeT
 gzyAkB/4eXQtoAUgFBYYVNcyx5aI5bwBfmq49AIAZVMBvrUUKexrSVyXOvg1Ij9hCNkrV8
 Q9kH3fSU66EK0RXKxSR0weA6K6hPy/hTlthOGUIrAYpDmT1f3bzHeJBFjZkRv78ECg+1sg
 rU4QKTvj9uUE08FulCqC4wHKe/ft/d2t9e9DvdWqQkazDYTQVHK3Wgnth69h3GrdiaSOm2
 ovq25meroIj26FBBchwv5AJfEsmkvGuPTJenO2lHD0r0IQ+gnCj/ZvbzD5iVUA==
X-Report-Abuse-To: abuse@transip.nl
X-Greylist: delayed 317 seconds by postgrey-1.37 at buxtehude;
 Thu, 04 Jun 2026 06:03:03 UTC
Delivered-To: submit@bugs.debian.org

Package: freeradius
Version: 3.2.7+dfsg-1+deb13u2

FreeRADIUS just had a security update release that fixes various memory
leaks and buffer overflows [0]. One of them has the description &quot; This
crash is before the packet is authenticated via the shared secret, so it
can be exploited by anyone who can send UDP packets to the server&quot;,
which makes the severity a bit higher than usual.

[0] https://www.freeradius.org/security/
]