Medium [CVE-2026-73242] Out-of-bounds memory access in Kerberos decryption
This medium-severity Red Hat Linux advisory covers CVE-2026-73242 affecting Red Hat Enterprise Linux 10, Red Hat package: freerdp.
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
FreeRDP is a free implementation of the Remote Desktop Protocol.
Prior to 3.30.0, FreeRDP's winpr/libwinpr/sspi/Kerberos/kerberos.c kerberos_DecryptMessage function fails to bound the peer-controlled GSS Wrap-token EC field before using it with RRC in IOV pointer offsets, allowing a malicious RDP peer to trigger out-of-bounds reads and in-place writes during CredSSP/NLA Kerberos decryption.
This issue is fixed in version 3.30.0. This occurs during CredSSP/NLA decryption and can lead to a denial of service or information disclosure.
An Important out-of-bounds memory vulnerability in FreeRDP's CredSSP/NLA Kerberos decryption allows a malicious RDP endpoint to execute arbitrary code or expose sensitive information on connected clients and servers. This flaw only affects FreeRDP 3.0.0 and newer, meaning RHEL 9 and older versions are not affected.
Red Hat severity: Moderate — CVSS 6.4 (CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:L/A:H). Weakness: CWE-125.
Affected Red Hat products: Red Hat Enterprise Linux 10. Red Hat does not currently list a fixing RHSA for this CVE.
Affected products named by the advisory: Red Hat package: freerdp.
- < 3.30.0
Official advisory · high-confidence parse· fetched 3 hours ago·verify at source
Mitigation checklist
- Use FreeRDP with Kerberos/NLA only against trusted RDP peers. As a client, avoid connecting to untrusted RDP servers; as a server, restrict inbound RDP to trusted clients using host firewall rules or network segmentation.
Official advisory · high-confidence parse· fetched 3 hours ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.