A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.
References
| Link | Resource |
|---|---|
| https://access.redhat.com/errata/RHSA-2025:9307 | Vendor Advisory |
| https://access.redhat.com/security/cve/CVE-2025-4478 | Vendor Advisory |
| https://bugzilla.redhat.com/show_bug.cgi?id=2365232 | Issue Tracking Permissions Required |
| https://github.com/FreeRDP/FreeRDP/pull/11573 | Patch |
Configurations
History
No history.
Information
Published : 2025-05-16 15:15
Updated : 2025-10-29 14:14
NVD link : CVE-2025-4478
Mitre link : CVE-2025-4478
CVE.ORG link : CVE-2025-4478
JSON object : View
Products Affected
freerdp
- freerdp
redhat
- enterprise_linux
CWE
CWE-476
NULL Pointer Dereference
