Logo
vulnerabilityCVE-2025-4478
Name
CVE-2025-4478
Source
NVD ( link)Debian ( link)
Description
A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
freerdp
Patched
freerdp3
Patched

Vulnerability Ratings#


6.5
CVSSv31
6.5
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.11.8
Not Affected
buildroot
master
2.11.8
Not Affected
yocto
kirkstone
2.6.1
Not Affected
yocto
master
2.11.8
Not Affected
yocto
master
3.26.0
Not Affected

Resolved with patches#


freerdp3 (yocto:scarthgap)

#
Title
Author
Resolve
1
transport: Initialize function pointers after resource
=?UTF-8?q?Jonas=20=C3=85dahl?= <jadahl@gmail.com>
CVE-2025-4478