suse · CVE-2019-11235

Quick triage

Priority: high Published: 2021-05-30 14:27:30 UTC Updated: 2026-03-05 06:18:44 UTC

View at Official suse advisory, NVD, CVE.org · CVE detail

Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.

Tracker summary

CVE-2019-11235 severity important: SUSE including 164 source package names (freeradius-3.0.13-10.el7_6, freeradius-3.0.17-4.module+el8.0.0+3108+851cb559, …), 363 product×package rows across 44 product lines (SLES for SAP Applications 11 SP3, SUSE Enterprise Storage 4, … (44 product lines)): Fixed 334, Known Not Affected 29.

Description:

FreeRADIUS before 3.0.19 mishandles the "each participant verifies that the received scalar is within a range, and that the received group element is a valid point on the curve being used" protection mechanism, aka a "Dragonblood" issue, a similar issue to CVE-2019-9498 and CVE-2019-9499.

cvelogic Threat Intelligence