CVE-2017-10979: Freeradius

Critical severity, CVSS 9.8. EPSS: 7% chance of exploitation in the next 30 days.

An FR-GV-202 issue in FreeRADIUS 2.x before 2.2.10 allows "Write overflow in rad_coalesce()" - this allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code.

Affected products

  • Freeradius Freeradius: version 2.0.0 only; version 2.0.1 only; version 2.0.2 only; version 2.0.3 only; version 2.0.4 only; version 2.0.5 only; …

Published 2017-07-17. Last modified 2026-06-17.