Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-67305

Опубликовано: 01 авг. 2026
Источник: redhat
CVSS3: 7.5

Описание

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can send a response with a data payload significantly larger than requested, causing arbitrary heap memory corruption that may enable remote code execution when a user performs a paste operation.

The FreeRDP Windows client contains a heap buffer overflow vulnerability. If a user pastes maliciously crafted, oversized clipboard data from an untrusted RDP server, it triggers memory corruption that may result in remote code execution.

Отчет

Red Hat products are not impacted by this vulnerability. The affected codebase (wfreerdp / wf_cliprdr.c) is exclusive to the Windows client, whereas Red Hat Enterprise Linux (RHEL) strictly utilizes and builds Linux clients for FreeRDP.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpNot affected
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpNot affected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2510027FreeRDP: FreeRDP Windows Client: Remote Code Execution via Heap Buffer Overflow in Clipboard Processing

7.5 High

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can send a response with a data payload significantly larger than requested, causing arbitrary heap memory corruption that may enable remote code execution when a user performs a paste operation.

nvd
около 1 месяца назад

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can send a response with a data payload significantly larger than requested, causing arbitrary heap memory corruption that may enable remote code execution when a user performs a paste operation.

debian
около 1 месяца назад

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow v ...

github
около 1 месяца назад

FreeRDP Windows client before 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can send a response with a data payload significantly larger than requested, causing arbitrary heap memory corruption that may enable remote code execution when a user performs a paste operation.

7.5 High

CVSS3