CVE-2025-4478: Freerdp
Medium severity, CVSS 6.5. EPSS: 0.5% chance of exploitation in the next 30 days.
A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system.
Affected products
- Freerdp Freerdp: from 3.0.0, before 3.16.0 (fixed in 3.16.0)
- Red Hat Enterprise Linux: version 10.0 only
Published 2025-05-16. Last modified 2026-06-30.