Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-23732

Опубликовано: 19 янв. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts cbData/remaining length and never validates against the minimum size implied by cx/cy. A malicious server can trigger a client‑side global buffer overflow, causing a crash (DoS). Version 3.21.0 contains a patch for the issue.

A flaw was found in FreeRDP. A malicious server can exploit a vulnerability in FastGlyph parsing, which improperly trusts data length without sufficient validation. This can lead to a client-side global buffer overflow, resulting in a denial of service (DoS) due to a crash. For this vulnerability to be exploited, a client must connect to a maliciously-configured server.

Отчет

For this vulnerability to be exploited, a client must connect to a maliciously-configured server. Red Hat recommends that FreeRDP clients are only used to connect to trusted servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6freerdpAffected
Red Hat Enterprise Linux 10freerdpFixedRHSA-2026:679907.04.2026
Red Hat Enterprise Linux 10freerdpFixedRHSA-2026:1903319.05.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportfreerdpFixedRHSA-2026:674307.04.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportfreerdpFixedRHSA-2026:1132328.04.2026
Red Hat Enterprise Linux 8freerdpFixedRHSA-2026:691807.04.2026
Red Hat Enterprise Linux 8.2 Advanced Update SupportfreerdpFixedRHSA-2026:1073427.04.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportfreerdpFixedRHSA-2026:1073527.04.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnfreerdpFixedRHSA-2026:1073527.04.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportfreerdpFixedRHSA-2026:1095127.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2430881freerdp: FreeRDP: Denial of Service via FastGlyph parsing buffer overflow

EPSS

Процентиль: 39%
0.00481
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts `cbData`/remaining length and never validates against the minimum size implied by `cx/cy`. A malicious server can trigger a client‑side global buffer overflow, causing a crash (DoS). Version 3.21.0 contains a patch for the issue.

CVSS3: 7.5
nvd
6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts `cbData`/remaining length and never validates against the minimum size implied by `cx/cy`. A malicious server can trigger a client‑side global buffer overflow, causing a crash (DoS). Version 3.21.0 contains a patch for the issue.

CVSS3: 7.5
debian
6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 5.3
fstec
6 месяцев назад

Уязвимость функции Glyph_Alloc() RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

CVSS3: 5.3
redos
около 2 месяцев назад

Уязвимость freerdp3

EPSS

Процентиль: 39%
0.00481
Низкий

6.5 Medium

CVSS3