Описание
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.
A flaw was found in FreeRDP.If a user connects to a malicious Remote Desktop (RDP) server, a security flaw in FreeRDP could cause the application to crash or allow the server to run unauthorized code on the user's system.
Отчет
This vulnerability in FreeRDP could allow a malicious Remote Desktop server to run unauthorized code or crash the connecting user's system. Red Hat users are only at risk if they use the FreeRDP client to connect to an untrusted or compromised server.
Меры по смягчению последствий
To mitigate this issue, users should avoid connecting to untrusted or unknown Remote Desktop Protocol (RDP) servers. Restricting FreeRDP client usage to only known and trusted RDP servers can reduce the risk of exploitation.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Not affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Will not fix | ||
| Red Hat Enterprise Linux 10 | freerdp | Fixed | RHSA-2026:36203 | 07.07.2026 |
| Red Hat Enterprise Linux 10.0 Extended Update Support | freerdp | Fixed | RHSA-2026:46393 | 27.07.2026 |
Показывать по
Ссылки на источники
Дополнительная информация
Статус:
8.8 High
CVSS3
Связанные уязвимости
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ...
FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.
Уязвимость функции gdi_CacheToSurface() RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании
8.8 High
CVSS3