Red Hat Enterprise Linux: denial of service
Medium4.2CVE-2026-14612 · Published Jul 3, 2026 · updated Jul 7, 2026
Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 device authorization handler can cause out-of-bounds memory access when processing an oversized response from a configured external OAuth2/OIDC Identity Provider. An attacker who controls or can man-in-the-middle the IdP endpoint may be able to trigger ipa-otpd to write or read one byte past the end of a fixed-size buffer. Exploitation requires FreeIPA to be configured with an external IdP, attacker control or MITM of that IdP, and a user to initiate the OAuth2 device authorization flow. The most likely impact is limited denial of service affecting the ipa-otpd daemon.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Red Hat Enterprise Linux 10 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 6 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 7 Product | all versions | No fix yet |
| Red Hat Enterprise Linux 8 Product | all versions | No fix yet |
| all versions | No fix yet | |
| Red Hat Enterprise Linux 9 Product | all versions | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:L
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-787
More Red Hat advisories
All Red Hat| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 3 | Red Hat GIMP: buffer overflow | High7.3 | No fix yet |
| Jul 3 | Red Hat Keycloak: improper access control | Medium4.3 | No fix yet |
| Jul 3 | Red Hat ClientResource: insecure direct object reference | Medium5.4 | No fix yet |
| Jul 3 | A flaw was found in the Fine-Grained Admin Permissions | Medium4.3 | No fix yet |
| Jul 3 | Red Hat HPLIP: privilege escalation | Critical9.8 | No fix yet |
| Jul 2 | Red Hat GIMP: memory corruption | Medium6.1 | No fix yet |