CVE Vulnerabilities

CVE-2025-4478

NULL Pointer Dereference

Published: May 16, 2025 | Modified: Oct 29, 2025
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
7.1 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Ubuntu
MEDIUM

A flaw was found in the FreeRDP used by Anacondas remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Freerdp Freerdp 3.0.0 (including) 3.16.0 (excluding)
Red Hat Enterprise Linux 10 RedHat freerdp-2:3.10.3-3.el10_0 *
Freerdp3 Ubuntu noble *
Freerdp3 Ubuntu oracular *
Freerdp3 Ubuntu plucky *
Freerdp3 Ubuntu upstream *

Potential Mitigations

References