Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-63652

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

A flaw was found in FreeRDP. An authenticated Remote Desktop Protocol (RDP) client can send a specially crafted Client Audio Formats Protocol Data Unit (PDU) to the server. This malformed PDU can cause a double-free vulnerability in the rdpsnd_server_recv_formats function, leading to the server reliably terminating. This issue can also result in allocator-dependent heap corruption, which may have further security implications.

Отчет

A double-free vulnerability exists in FreeRDP's rdpsnd_server_recv_formats function within the rdpsnd server channel. An authenticated remote RDP client can send a malformed Client Audio Formats PDU with an invalid cbSize parameter, causing memory to be freed without zeroing the client_formats pointer. Upon session teardown, rdpsnd_server_context_free attempts to free the dangling pointer again. This results in server process termination and potential heap corruption, causing a denial of service.

Меры по смягчению последствий

To mitigate this issue, disable audio redirection on the FreeRDP server configuration if remote audio capability is not required.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpAffected
Red Hat Enterprise Linux 10freerdpFixedRHSA-2026:6137831.08.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-1341
https://bugzilla.redhat.com/show_bug.cgi?id=2519822FreeRDP: FreeRDP: Denial of Service and heap corruption via malformed RDP audio PDU

EPSS

Процентиль: 27%
0.00342
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
15 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

nvd
15 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, rdpsnd_server_recv_formats in channels/rdpsnd/server/rdpsnd_main.c frees context->client_formats on a malformed Client Audio Formats PDU without clearing the owning pointer or num_client_formats. An authenticated RDP client can trigger an error such as a cbSize larger than the remaining record, leave the dangling pointer in the server context, and cause rdpsnd_server_context_free to free the same allocation again at session teardown. This reliably terminates the server and can create allocator-dependent heap corruption. This issue is fixed in version 3.28.0.

debian
15 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 6.5
fstec
2 месяца назад

Уязвимость функции rdpsnd_server_recv_formats() файла channels/rdpsnd/server/rdpsnd_main.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 27%
0.00342
Низкий

6.5 Medium

CVSS3