PT-2026-55548 · Freeipa · Ipa-Otpd

·

CVE-2026-14612

·

Published

2026-07-03

·

Updated

2026-07-07

CVSS v3.1

4.2

Medium

VectorAV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
Name of the Vulnerable Software and Affected Versions FreeIPA ipa-otpd daemon (affected versions not specified)
Description Two off-by-one errors exist in the OAuth2 device authorization handler of the ipa-otpd daemon. These errors can lead to out-of-bounds memory access when the daemon processes an oversized response from a configured external OAuth2/OIDC Identity Provider (IdP). An attacker who controls the IdP endpoint or performs a man-in-the-middle attack on it can trigger the daemon to read or write one byte beyond the end of a fixed-size buffer. This issue requires FreeIPA to be configured with an external IdP and a user to start the OAuth2 device authorization flow. The primary impact is a denial of service affecting the ipa-otpd daemon.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14612

Affected Products

Ipa-Otpd