Bug 2510915 - CVE-2026-67298 freerdp: FreeRDP: Denial of Service via integer underflow in RAIL channel handling [fedora-all]
Summary: CVE-2026-67298 freerdp: FreeRDP: Denial of Service via integer underflow in R...
Keywords:
Status: CLOSED CURRENTRELEASE
Alias: None
Product: Fedora
Classification: Fedora
Component: freerdp
Version: rawhide
Hardware: Unspecified
OS: Unspecified
high
high
Target Milestone: ---
Assignee: Simone Caronni
QA Contact: Fedora Extras Quality Assurance
URL:
Whiteboard: {"flaws": ["81ad3b1f-607d-481a-828a-f...
Depends On:
Blocks: CVE-2026-67298
TreeView+ depends on / blocked
 
Reported: 2026-08-04 09:38 UTC by Srikanth Balasubramanian
Modified: 2026-08-17 11:54 UTC (History)
4 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed: 2026-08-17 11:54:43 UTC
Type: ---
Embargoed:


Attachments (Terms of Use)

Description Srikanth Balasubramanian 2026-08-04 09:38:12 UTC
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.

FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler (rail_server_handle_messages() in channels/rail/server/rail_main.c). When processing a RAIL PDU header, the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled orderLength field without first verifying orderLength is at least the header length. For orderLength values 0..3 this causes an unsigned integer underflow to a very large size, which bypasses the Stream_EnsureRemainingCapacity() capacity check (due to pointer arithmetic wraparound) and is then passed to WTSVirtualChannelRead(), resulting in an out-of-bounds heap write. A malicious or compromised RDP client can exploit this to corrupt the heap and crash the server. Fixed in FreeRDP 3.29.0.

Comment 1 Ondrej Holy 2026-08-17 11:54:43 UTC
We have already 3.30 in Fedora.


Note You need to log in before you can comment on or make changes to this bug.