CVE-2024-3596

critical
Published 2024-07-31 · Modified 2024-08-06
CVSS v3
9.0
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
CVSS v2
VIR risk
9.0

Description

Important: freeradius security update

Predictions

Exploit likelihood
93%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-4935.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/9/ALSA-2024-9474.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-4936.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:4936

vendor Authored 2026-05-27

Vendor advisory: alma — https://errata.almalinux.org/8/ALSA-2024-8860.html

vendor Authored 2026-05-27

Vendor advisory: alma — https://bugzilla.redhat.com/2263240

vendor Authored 2026-05-27

Vendor advisory: alma — https://access.redhat.com/errata/RHSA-2024:8860

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:4935

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:9474

vendor Authored 2026-05-27

Vendor advisory: suse — https://www.suse.com/security/cve/CVE-2024-3596.html

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2024-3596

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:4936

vendor Authored 2026-05-27

Vendor advisory: rocky — https://errata.rockylinux.org/RLSA-2024:8860

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:9474

vendor Authored 2026-05-27

Vendor advisory: redhat — https://access.redhat.com/errata/RHSA-2024:4935

OS impact

OSVersionStatusFixed in
redhat rhel9fixed
rockylinux rocky8fixed
debian debianbookwormaffected
debian debianbullseyeaffected
debian debianforkyfixed3.2.5+dfsg-1
debian debiansidfixed3.2.5+dfsg-1
debian debiantrixiefixed3.2.5+dfsg-1
suse slesaffected
rockylinux rocky9fixed

Application impact

VendorProductVersionsFixed
freeradiusfreeradius{"endExcluding":"3.0.27"}3.0.27
broadcombrocade_sannav-

References

CWEs

CWE-354 CWE-924

Verify integrity in audit chain (admin only). AS-IS.