Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67297

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 6.5

Описание

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.

A vulnerability in FreeRDP allows a malicious RD Gateway to bypass client-side size limits by sending oversized chunked HTTP responses. This exhausts the client's memory, resulting in a Denial of Service (DoS).

Отчет

A Moderate vulnerability in FreeRDP 3.x allows a malicious or compromised Remote Desktop Gateway to exhaust client memory by sending oversized chunked HTTP responses that bypass the 64 MiB size cap. This flaw affects FreeRDP 3.x clients connecting to untrusted endpoints; RHEL 9 and older releases ship earlier FreeRDP versions that lack this code path and are not affected.

Меры по смягчению последствий

To mitigate this issue, FreeRDP clients should only connect to trusted Remote Desktop Gateway endpoints. Avoiding connections to untrusted or potentially compromised gateways will prevent exposure to malicious servers that could exploit this vulnerability by sending oversized chunked HTTP responses.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpNot affected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-770
https://bugzilla.redhat.com/show_bug.cgi?id=2509986FreeRDP: FreeRDP: Resource exhaustion due to oversized chunked HTTP responses

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 7.5
ubuntu
около 1 месяца назад

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.

CVSS3: 7.5
nvd
около 1 месяца назад

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.

CVSS3: 7.5
debian
около 1 месяца назад

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when pr ...

CVSS3: 7.5
github
около 1 месяца назад

FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.

CVSS3: 7.5
fstec
около 2 месяцев назад

Уязвимость функции http_response_recv_body() файла libfreerdp/core/gateway/http.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании

6.5 Medium

CVSS3