PT-2026-29136 · Freerdp+4 · Freerdp+4
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.24.2
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. The
progressive decompress tile upgrade() function detects a mismatch through progressive rfx quant cmp equal() but only emits a warning, allowing execution to continue. A wrapped value (247) is used as a shift exponent, leading to undefined behavior and a loop of approximately 80 billion iterations, resulting in a CPU denial of service (DoS).Recommendations
Update to version 3.24.2 or later.
Exploit
Fix
DoS
Unchecked Return Value
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freerdp
Linuxmint
Red Os
Rocky Linux
Ubuntu