FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, FastGlyph parsing trusts `cbData`/remaining length and never validates against the minimum size implied by `cx/cy`. A malicious server can trigger a client‑side global buffer overflow, causing a crash (DoS). Version 3.21.0 contains a patch for the issue.
This issue has been addressed in the following products: Red Hat Enterprise Linux 9 Via RHSA-2026:6340 https://access.redhat.com/errata/RHSA-2026:6340
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.6 Extended Update Support Via RHSA-2026:6727 https://access.redhat.com/errata/RHSA-2026:6727
This issue has been addressed in the following products: Red Hat Enterprise Linux 10.0 Extended Update Support Via RHSA-2026:6743 https://access.redhat.com/errata/RHSA-2026:6743
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:6799 https://access.redhat.com/errata/RHSA-2026:6799
This issue has been addressed in the following products: Red Hat Enterprise Linux 8 Via RHSA-2026:6918 https://access.redhat.com/errata/RHSA-2026:6918
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.4 Extended Update Support Via RHSA-2026:6958 https://access.redhat.com/errata/RHSA-2026:6958
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.0 Update Services for SAP Solutions Via RHSA-2026:9640 https://access.redhat.com/errata/RHSA-2026:9640
This issue has been addressed in the following products: Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions Via RHSA-2026:9641 https://access.redhat.com/errata/RHSA-2026:9641
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions Red Hat Enterprise Linux 8.8 Telecommunications Update Service Via RHSA-2026:10076 https://access.redhat.com/errata/RHSA-2026:10076
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.2 Advanced Update Support Via RHSA-2026:10734 https://access.redhat.com/errata/RHSA-2026:10734
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On Via RHSA-2026:10735 https://access.redhat.com/errata/RHSA-2026:10735
This issue has been addressed in the following products: Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support Red Hat Enterprise Linux 8.6 Update Services for SAP Solutions Red Hat Enterprise Linux 8.6 Telecommunications Update Service Via RHSA-2026:10951 https://access.redhat.com/errata/RHSA-2026:10951
This issue has been addressed in the following products: Red Hat Enterprise Linux 7 Extended Lifecycle Support Via RHSA-2026:11323 https://access.redhat.com/errata/RHSA-2026:11323