VDB
BDU%3A2026-00660
BDU%3A2026-00660
PUBLISHED
CVSS 5.5 MEDIUM
Уязвимость функции Glyph_Alloc() RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании
Risk Scores
CVSS 4.0
5.5
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:P
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| FreeRDP | FreeRDP | * |
| АО «ИВК», Free Software Foundation, Inc. | АЛЬТ СП 10, FreeRDP |
Timeline
- Jan 19, 2026 CVE Published
- Jan 27, 2026 CVE Updated
References
- https://github.com/FreeRDP/FreeRDP/releases/tag/3.21.0 advisory
- https://altsp.su/obnovleniya-bezopasnosti/ advisory
- https://github.com/FreeRDP/FreeRDP/blob/f96ee2a6dd02739325c2a4e36a14978b561f00ea/libfreerdp/cache/glyph.c#L463-L480 url
- https://github.com/FreeRDP/FreeRDP/blob/f96ee2a6dd02739325c2a4e36a14978b561f00ea/libfreerdp/codec/color.c#L261-L277 url
- https://github.com/FreeRDP/FreeRDP/blob/f96ee2a6dd02739325c2a4e36a14978b561f00ea/libfreerdp/core/graphics.c#L138 url
- https://github.com/FreeRDP/FreeRDP/blob/f96ee2a6dd02739325c2a4e36a14978b561f00ea/libfreerdp/core/orders.c#L2186C17-L2199 url
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7qxp-j2fj-c3pp exploit