Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67296

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

A flaw was found in FreeRDP. A remote attacker can exploit a vulnerability in the Remote Desktop Protocol (RDP) Enhanced Input (RDPEI) server channel handler. By sending a malicious RDPEI message with an oversized declared body length, the attacker can force the server to allocate excessive memory, leading to a denial of service (DoS).

Отчет

A Moderate denial of service (DoS) vulnerability in FreeRDP's RDPEI server channel affects systems acting as an RDP server or proxy. A remote, unauthenticated attacker can send a specially crafted RDP message to trigger excessive memory allocation, causing service disruption.

Меры по смягчению последствий

To mitigate this do not expose FreeRDP server/proxy/shadow (freerdp-shadow-cli / freerdp-proxy) to untrusted networks—allow only trusted clients via firewall, or disable those services if unused.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpAffected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-20
https://bugzilla.redhat.com/show_bug.cgi?id=2510029FreeRDP: FreeRDP: Denial of Service due to RDPEI message processing

EPSS

Процентиль: 27%
0.00344
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

CVSS3: 7.5
nvd
около 1 месяца назад

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

CVSS3: 7.5
debian
около 1 месяца назад

FreeRDP before 3.29.0 contains a denial of service vulnerability in th ...

CVSS3: 7.5
github
около 1 месяца назад

FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость функции rdpei_server_handle_messages() файла channels/rdpei/server/rdpei_main.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 27%
0.00344
Низкий

6.5 Medium

CVSS3