Fedora Account System
Red Hat Associate
Red Hat Customer
FreeRDP before 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler that fails to validate maximum PDU body length before stream allocation. A malicious RDP client can send a header-only RDPEI message with a large declared body length to force excessive memory allocation on the server.
This issue has been addressed in the following products: Red Hat Enterprise Linux 10 Via RHSA-2026:61378 https://access.redhat.com/errata/RHSA-2026:61378