FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.5.1, a malicious server can crash the FreeRDP client by sending invalid huge allocation size. Version 3.5.1 contains a patch for the issue. No known workarounds are available. https://github.com/FreeRDP/FreeRDP/commit/5e5d27cf310e4c10b854be7667bfb7a5d774eb47 https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mxv6-2cw6-m3mx https://oss-fuzz.com/testcase-detail/5559242514825216
Created freerdp tracking bugs for this issue: Affects: fedora-38 [bug 2276972] Affects: fedora-39 [bug 2276974] Affects: fedora-40 [bug 2276975] Created freerdp1.2 tracking bugs for this issue: Affects: epel-7 [bug 2276973] Created freerdp2 tracking bugs for this issue: Affects: fedora-40 [bug 2276976]
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2024:9092 https://access.redhat.com/errata/RHSA-2024:9092