CVE-2025-4478

A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

Configuration 2 (hide)

cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*

History

14 Oct 2025, 20:39

Type Values Removed Values Added
CPE cpe:2.3:o:redhat:enterprise_linux:10.0:*:*:*:*:*:*:*
cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
References () https://access.redhat.com/errata/RHSA-2025:9307 - () https://access.redhat.com/errata/RHSA-2025:9307 - Vendor Advisory
References () https://access.redhat.com/security/cve/CVE-2025-4478 - () https://access.redhat.com/security/cve/CVE-2025-4478 - Vendor Advisory
References () https://bugzilla.redhat.com/show_bug.cgi?id=2365232 - () https://bugzilla.redhat.com/show_bug.cgi?id=2365232 - Issue Tracking, Permissions Required
References () https://github.com/FreeRDP/FreeRDP/pull/11573 - () https://github.com/FreeRDP/FreeRDP/pull/11573 - Patch
First Time Freerdp freerdp
Redhat
Freerdp
Redhat enterprise Linux

29 Jul 2025, 19:15

Type Values Removed Values Added
References
  • () https://github.com/FreeRDP/FreeRDP/pull/11573 -

23 Jun 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-16 15:15

Updated : 2025-10-14 20:39


NVD link : CVE-2025-4478

Mitre link : CVE-2025-4478

CVE.ORG link : CVE-2025-4478


JSON object : View

Products Affected

redhat

  • enterprise_linux

freerdp

  • freerdp
CWE
CWE-476

NULL Pointer Dereference