Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-24677

Опубликовано: 09 фев. 2026
Источник: redhat
CVSS3: 5.3

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts server-controlled dimensions and does not validate the source buffer size, leading to an out-of-bounds read in sws_scale. This vulnerability is fixed in 3.22.0.

A heap buffer overflow has been discovered in FreeRDP. ecam_encoder_compress_h264 trusts server-controlled dimensions and does not validate the source buffer size, leading to an out-of-bounds read in sws_scale.

Отчет

Availability impact is limited to the FreeRDP instance on Red Hat Products. General system availability is not at risk.

Меры по смягчению последствий

Mitigation for this issue is either not available or the currently available options do not meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpNot affected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpNot affected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-825
https://bugzilla.redhat.com/show_bug.cgi?id=2438206freerdp: FreeRDP has a heap-buffer-overflow in ecam_encoder_compress_h264

5.3 Medium

CVSS3

Связанные уязвимости

CVSS3: 9.1
ubuntu
6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts server-controlled dimensions and does not validate the source buffer size, leading to an out-of-bounds read in sws_scale. This vulnerability is fixed in 3.22.0.

CVSS3: 9.1
nvd
6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.22.0, ecam_encoder_compress_h264 trusts server-controlled dimensions and does not validate the source buffer size, leading to an out-of-bounds read in sws_scale. This vulnerability is fixed in 3.22.0.

CVSS3: 9.1
debian
6 месяцев назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 9.1
fstec
6 месяцев назад

Уязвимость функции ecam_encoder_compress_h264() реализации протокола удалённого рабочего стола FreeRDP, позволяющая нарушителю получить доступ к конфиденциальным данным или вызвать отказ в обслуживании

CVSS3: 9.1
redos
около 2 месяцев назад

Уязвимость freerdp3

5.3 Medium

CVSS3