Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55564

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 5.4

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number instead of greater than or equal to it. A malicious RDP server can use GLYPH_FRAGMENT_USE replay in update_process_glyph_fragments to make the default cache receive index 254 when cache->number is 254, reading one pointer beyond the entries array and dereferencing it as a glyph. This can crash the client and may disclose adjacent heap data. This issue is fixed in version 3.27.0.

A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can exploit an out-of-bounds read vulnerability in the glyph_cache_get function. By sending crafted glyph fragments, the server can cause the client to read beyond the intended memory buffer. This can lead to a client crash, resulting in a Denial of Service (DoS), and potentially disclose sensitive adjacent heap data.

Меры по смягчению последствий

Restrict FreeRDP client connections to trusted Remote Desktop Protocol (RDP) servers only. Avoid connecting to untrusted or potentially malicious RDP servers to prevent exploitation of this client-side vulnerability. If FreeRDP client functionality is not essential, consider removing the freerdp package and its dependencies.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpFix deferred
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpFix deferred
Red Hat Enterprise Linux 8freerdpFix deferred
Red Hat Enterprise Linux 9freerdpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2519813FreeRDP: FreeRDP: Out-of-bounds read in glyph cache leads to denial of service and information disclosure

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
ubuntu
28 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number instead of greater than or equal to it. A malicious RDP server can use GLYPH_FRAGMENT_USE replay in update_process_glyph_fragments to make the default cache receive index 254 when cache->number is 254, reading one pointer beyond the entries array and dereferencing it as a glyph. This can crash the client and may disclose adjacent heap data. This issue is fixed in version 3.27.0.

CVSS3: 5.4
nvd
28 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, the glyph_cache_get function in libfreerdp/cache/glyph.c checks whether index is greater than cache->number instead of greater than or equal to it. A malicious RDP server can use GLYPH_FRAGMENT_USE replay in update_process_glyph_fragments to make the default cache receive index 254 when cache->number is 254, reading one pointer beyond the entries array and dereferencing it as a glyph. This can crash the client and may disclose adjacent heap data. This issue is fixed in version 3.27.0.

CVSS3: 5.4
debian
28 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 5.4
redos
23 дня назад

Уязвимость freerdp3

CVSS3: 5.4
redos
23 дня назад

Уязвимость freerdp3

5.4 Medium

CVSS3