Name
CVE-2025-4478
Description
A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.
CWEs
Published Date
Updated Date
Workaround
-
Advisories
https://access.redhat.com/errata/RHSA-2025:9307Vendor Advisory
https://access.redhat.com/security/cve/CVE-2025-4478Vendor Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=2365232Issue Tracking
Analysis#
Vulnerability Ratings#
6.5
CVSSv31
6.5
CVSSv31
NaN
other
Others affected components#
Resolved with patches#
freerdp3 (yocto:scarthgap)
#
Title
Author
Resolve
1
transport: Initialize function pointers after resource
=?UTF-8?q?Jonas=20=C3=85dahl?= <jadahl@gmail.com>
CVE-2025-4478