Описание
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.
A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can send specially crafted AVC444 graphics updates. This can cause the pool_decode_rect function to enter an infinite loop when decoding AVC444 metablocks with an excessive number of region rectangles. The vulnerability leads to a denial of service (DoS) by consuming CPU resources and preventing normal client operation.
Меры по смягчению последствий
To mitigate this issue, users should avoid connecting FreeRDP clients to untrusted or unverified RDP servers. Restricting RDP client connections to known, legitimate servers reduces the risk of encountering a malicious server exploiting this vulnerability.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Affected | ||
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freerdp | Affected | ||
| Red Hat Enterprise Linux 8 | freerdp | Affected | ||
| Red Hat Enterprise Linux 9 | freerdp | Affected |
Показывать по
Дополнительная информация
Статус:
EPSS
6.5 Medium
CVSS3
Связанные уязвимости
[GHSA-m85m-3qxv-63h5: Infinite loop / CPU DoS in pool_decode_rect]
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.
FreeRDP versions before 3.31.0 contain an infinite-loop denial of serv ...
FreeRDP versions before 3.31.0 contain an infinite-loop denial of service in the pool_decode_rect function when decoding AVC444 metablocks with more region rectangles than preallocated worker array size. A malicious RDP server can send crafted AVC444 graphics updates causing the threaded decode path to loop indefinitely, consuming CPU and preventing normal client operation.
EPSS
6.5 Medium
CVSS3