Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2f6r-w7g3-4q27

Опубликовано: 15 сент. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 7.1
CVSS3: 6.5

Описание

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.

EPSS

Процентиль: 28%
0.00346
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-835

Связанные уязвимости

CVSS3: 6.5
ubuntu
4 дня назад

[GHSA-m85m-3qxv-63h5: Infinite loop / CPU DoS in pool_decode_rect]

CVSS3: 6.5
redhat
4 дня назад

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.

CVSS3: 6.5
nvd
4 дня назад

FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.

CVSS3: 6.5
debian
4 дня назад

FreeRDP versions before 3.31.0 contain an infinite-loop denial of serv ...

EPSS

Процентиль: 28%
0.00346
Низкий

7.1 High

CVSS4

6.5 Medium

CVSS3

Дефекты

CWE-835