Fedora Account System
Red Hat Associate
Red Hat Customer
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:61378 https://access.redhat.com/errata/RHSA-2026:61378
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:68706 https://access.redhat.com/errata/RHSA-2026:68706