Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67291

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

A heap out-of-bounds read vulnerability in FreeRDP allows an unauthenticated, malicious RDP server to cause a Denial of Service. By sending a specially crafted glyph fragment update, the server forces the client to read beyond its allocated memory, crashing the application.

Отчет

A Moderate heap out-of-bounds read in FreeRDP affects Red Hat products by allowing an untrusted RDP server to remotely crash a connecting client without authentication, resulting in a loss of application availability.

Меры по смягчению последствий

To mitigate this issue, avoid connecting FreeRDP clients to untrusted or potentially malicious RDP servers. If such connections are required, run the client on a dedicated, isolated system so a client crash is contained and does not impact other workloads.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpAffected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2510010FreeRDP: FreeRDP: Denial of Service via heap out-of-bounds read

EPSS

Процентиль: 26%
0.00335
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

CVSS3: 7.5
nvd
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

CVSS3: 7.5
debian
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap ou ...

CVSS3: 7.5
github
около 1 месяца назад

FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a heap out-of-bounds read in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. When handling a GLYPH_FRAGMENT_ADD update, the code reads a one-byte server-controlled declared fragment size but does not verify it fits within the remaining received buffer before allocating and copying that many bytes. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in an out-of-bounds read and client crash.

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость функций update_process_glyph_fragments() и glyph_cache_fragment_put() файла libfreerdp/cache/glyph.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 26%
0.00335
Низкий

6.5 Medium

CVSS3