CVE-2025-4478

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

No history.

Information

Published : 2025-05-16 15:15

Updated : 2025-10-29 14:14


NVD link : CVE-2025-4478

Mitre link : CVE-2025-4478

CVE.ORG link : CVE-2025-4478


JSON object : View

Products Affected

freerdp

  • freerdp

redhat

  • enterprise_linux
CWE
CWE-476

NULL Pointer Dereference