Описание
FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.
A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol (RDP). This use-after-free vulnerability exists in the smartcard RDPDR device handler. A remote attacker could exploit this by triggering a worker thread creation failure after device registration during channel setup. This leads to the deallocation of a device pointer while the device manager (devman) still retains a reference, which can result in a denial of service (crash) or potentially lead to arbitrary code execution.
Меры по смягчению последствий
To reduce the attack surface, disable smartcard redirection within FreeRDP client configurations if this functionality is not required. This action prevents the vulnerable smartcard RDPDR device handler from being utilized. Refer to FreeRDP documentation for specific instructions on disabling smartcard redirection.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat Enterprise Linux 10 | freerdp | Fix deferred | ||
| Red Hat Enterprise Linux 6 | freerdp | Out of support scope | ||
| Red Hat Enterprise Linux 7 | freerdp | Fix deferred | ||
| Red Hat Enterprise Linux 8 | freerdp | Fix deferred | ||
| Red Hat Enterprise Linux 9 | freerdp | Fix deferred |
Показывать по
Дополнительная информация
Статус:
EPSS
3.1 Low
CVSS3
Связанные уязвимости
[GHSA-j5mq-3349-gwmm: channels,smartcard worker creation failure frees a devman-owned device]
FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.
FreeRDP before 3.31.0 contains a use-after-free vulnerability in the s ...
FreeRDP before 3.31.0 contains a use-after-free vulnerability in the smartcard RDPDR device handler when worker thread creation fails after device registration. Attackers can trigger thread creation failure during channel setup to cause device pointer deallocation while devman retains a reference, leading to crash or code execution.
EPSS
3.1 Low
CVSS3