Red Hat Linux RHEL & SELinux Vulnerabilities & Security Advisories
1648 advisories tracked · Red Hat Security Data API · 2 listed in the CISA Known Exploited Vulnerabilities catalog
Every row below is a published Red Hat Linux advisory that VulniPulse classified as RHEL & SELinux, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 35 critical, 622 high, 819 medium, 170 low.
Android app · Google Play
Monitor Red Hat CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Source
Red Hat Security Data API
Red Hat Enterprise Linux errata (RHSA) via the official Red Hat Security Data API — CVE severity, CVSS and affected packages. A credential-free official source.
Latest Red Hat RHEL & SELinux advisories
Medium [CVE-2026-59088] denial of service via signed integer overflow in fli file processing
A flaw was found in GIMP. A signed integer overflow vulnerability exists in the `file-fli` plugin when processing FLI image files. This occurs due to an incorrect calculation during memory allocation for image buffers, where the multiplication of image width and height can exceed the maximum integer value. A remote attacker could exploit this by tricking a user into opening a specially crafted FLI file, leading to the application crashing and resulting in a denial of service. This Moderate impact flaw in GIMP's FLI file processing plugin can lead to a denial of service. The vulnerability requires user interaction, as an attacker must convince a local user to open a specially crafted FLI image file, which would cause the GIMP application to crash due to an integer overflow during memory allocation. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-190. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE.
Medium [CVE-2026-66486] GNU cpio: Terminal control sequence injection via crafted archive member names
GNU cpio is vulnerable to improper encoding or escaping of output in its archive member listing functionality. When listing archive members via cpio -it, member names are printed directly to output without quoting or escaping. An attacker can craft a cpio archive containing member names with embedded newline characters or ANSI escape sequences, causing forged listing entries or terminal control sequence injection when the listing is displayed. This issue has been fixed in commit 2ff9600c9ef32e88759843cdbde74c8db5ae9b30 All Red Hat cpio packages (RHEL 6 through 10, RHIVOS) ship versions well below the fix and are affected. Red Hat severity: Moderate — CVSS 6.1 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:H/A:N). Weakness: CWE-94. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cpio.
Medium [CVE-2026-66485] GNU cpio: Denial of Service via uncontrolled memory allocation from crafted archives
GNU cpio is vulnerable to an uncontrolled memory allocation in the make_path function at src/makepath.c. The function uses alloca to allocate stack memory based on the length of argpath, which is derived from an archive-controlled pathname during extraction. A malicious cpio archive containing a sufficiently long nested pathname causes an unbounded stack allocation, resulting in a stack overflow and crash of the cpio process. An attacker who can supply a crafted cpio archive to a victim who extracts it can cause a denial of service. This issue has been fixed in commit 3cd514031371d8aeeaf2048aa10103e02831aaa9 This vulnerability involves uncontrolled memory allocation when processing specially crafted cpio archives. This results in a denial of service (DoS) for the affected system. All Red Hat cpio packages (RHEL 6 through 10, RHIVOS) ship versions well below the fix and are affected. Red Hat severity: Moderate — CVSS 5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat Hardened Images. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: cpio.
Medium [CVE-2026-72522] Denial of Service due to incorrect Unicode surrogate handling
libexpat before 2.8.3 has an out-of-bounds read and resultant infinite loop because low surrogates are treated the same as high surrogates during Unicode processing in the *_toUtf16 functions. An attacker can exploit the resulting out-of-bounds read to trigger an infinite loop, causing a denial of service (DoS). A denial of service (DoS) flaw was found in libexpat's handling of Unicode surrogate pairs. An attacker providing specially crafted XML input to an application parsing untrusted data can trigger an out-of-bounds read and an infinite loop, leading to high CPU usage and system resource exhaustion. Red Hat severity: Moderate — CVSS 6.2 (CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Hardened Images; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat lists Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4 as not affected. Red Hat fixing advisory: RHSA-2026:54869. Affected products named by the advisory: Red Hat package: firefox; Red Hat package: thunderbird; Red Hat package: mingw-expat.
Medium [CVE-2026-19016] Authorization bypass allows arbitrary session deletion via transaction API
Consul Community Edition and Consul Enterprise 1.19.1 through 2.0.2 did not enforce the {{session:write}} ACL permission for session deletion operations submitted through the transaction API. An authenticated caller with network access to the Consul server RPC port could delete arbitrary sessions without holding the required permission. This vulnerability, CVE-2026-19016, is fixed in Consul 2.0.3 and Consul Enterprise 1.21.17, 1.22.11, and 2.0.3. A flaw was found in Consul. This allows an attacker to delete arbitrary sessions without the necessary permissions, leading to unauthorized session termination. Red Hat severity: Moderate — CVSS 4.2 (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L). Weakness: CWE-639. Affected Red Hat products: Red Hat Enterprise Linux 8. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: grafana.
Medium [CVE-2026-19079] toctou race condition in fixfiles allows arbitrary selinux label manipulation
A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. When running fixfiles relabel or fixfiles restore, the script used find and chcon commands to locate and relabel unlabeled files under /tmp and other directories. A local attacker could exploit a race window between the file discovery and the label change operation by swapping directory components with symlinks, causing chcon to follow the symlink and modify SELinux labels on arbitrary system files. This could undermine SELinux mandatory access control protections on critical files such as /etc/shadow. Red Hat ships policycoreutils with the fixfiles script in all supported RHEL versions. The vulnerable /tmp cleanup code path has been present in fixfiles for many years. Red Hat product impact analysis is required to determine which specific shipped versions of policycoreutils include the vulnerable code and whether backporting the upstream fix is necessary. The vulnerability requires local access, winning a race condition, and an administrator running fixfiles relabel or fixfiles restore, which limits the practical attack surface. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N). Weakness: CWE-367.
Medium [CVE-2025-49506] Information disclosure via timing attack in password validation
APR-util versions 1.6.3 (and earlier) function apr_password_validate() was not constant-time with regards to hashes or passwords comparisons, potentially leaking their content via a side channel timing attack particularly on platforms without crypt() such as Windows, BeOS, NetWare, or Android. Users are recommended to upgrade to version 1.6.4, which fixes this issue. A flaw was found in Apache Portable Runtime Utility (apr-util). By observing the time differences in comparisons, an attacker could potentially deduce the content of sensitive information like password hashes. This vulnerability is assessed as Low Impact due to significant practical exploitation barriers. While the theoretical outcome of a successful timing attack is hash disclosure (Confidentiality: High), isolating microsecond-level comparison differences over a network is rendered practically infeasible by unpredictable network latency, packet jitter, and server scheduling noise (Attack Complexity: High). Additionally, RHEL environments natively rely on the system crypt() implementation for standard password checks, bypassing the vulnerable non-constant-time fallback code path in standard deployment scenarios. Red Hat severity: Low — CVSS 5.9 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N). Weakness: CWE-208.
Medium [CVE-2026-69153] Information disclosure via crafted sourceMappingURL
PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.19, if from is unset, an attacker can cause PreviousMap.loadFile() to read an unintended source-map file by supplying an absolute or directory-traversal sourceMappingURL. The resulting map’s sources and sourcesContent may then be exposed to the application. This issue is fixed in version 8.5.19. A flaw was found in PostCSS. A remote attacker can exploit this vulnerability by providing a specially crafted sourceMappingURL when a specific configuration (the 'from' parameter) is not set. This can cause the application to read and expose unintended source-map files, potentially revealing sensitive information about the application's source code. Red Hat rates this flaw as Moderate because the information disclosed is limited to files with a.map extension. Source map files may contain source code paths and content, but the attacker cannot read arbitrary files on the system. Exploitation requires the application to process attacker-controlled CSS through PostCSS on the server side. Red Hat severity: Moderate — CVSS 5.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N). Weakness: CWE-22.
Medium [CVE-2026-18477] TOCTOU in incremental dumpdir 'X' rename handling allows restore path escape
A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local attacker with write access to a directory being backed up to influence the restore process if the attacker has access to the system where the restore is being performed. During restoration, files or directories may be created, renamed or overwritten outside the intended extraction directory. This could lead to unauthorized file modification or, in some cases, privilege escalation. Exploitation does not require the attacker to modify or craft the archive, and standard backup and restore workflows—including extracting into a newly created directory without using the -P option do not mitigate the issue. This issue affects GNU tar incremental backup and restore (-g/-G). A local attacker who can write to content included in an incremental backup, and who can also access the system where that backup is later restored, may cause the restore to create, rename, or overwrite paths outside the intended extraction directory via a TOCTOU race in dumpdir 'X' handling. Red Hat is assessing impact for the tar package in supported products. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:N). Weakness: CWE-367.
Medium [CVE-2026-18651] SASL PLAIN bind installs connection credentials before account-lock check, allowing continued access as a locked account
A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind credentials before performing the account-lock check. If the account is subsequently found to be locked, the bind is reported as failed to the client, but the already-installed authenticated state on the connection is not reverted. A client that supplies valid credentials for an account that has been administratively locked can continue to use the same connection with that account's privileges, defeating account lock as an access-revocation control. This flaw lets a user authenticate to an already-locked account (nsAccountLock: true) via SASL PLAIN, using that account's own correct password. The server checks the password before it checks the lock, so the connection becomes authenticated even though the client is told the bind failed. After bind, the user can read and modify what that account was already permitted to touch - no escalation and access beyond it's own rights. Red Hat severity: Moderate — CVSS 5.4 (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-287. Affected Red Hat products: Red Hat Directory Server 11; Red Hat Directory Server 12; Red Hat Directory Server 13; Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat lists Red Hat Enterprise Linux 6 as not affected.
Medium [CVE-2026-18508] --one-top-level hardlink targets not confined to top-level directory enabling arbitrary file overwrite
A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confined to the designated top-level directory and may resolve relative to the extraction working directory. A crafted archive can create hardlinks that escape the intended boundary and, when combined with a preexisting symbolic link under the working directory, may allow writing outside that boundary during a single extraction. Red Hat Enterprise Linux is affected. This issue only applies when the --one-top-level option is used to extract an untrusted archive. Default tar extraction without --one-top-level is not impacted by this specific boundary failure. Users should avoid using --one-top-level as the sole confinement mechanism for untrusted archives until fixed packages are available. Red Hat severity: Moderate — CVSS 4.4 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N). Weakness: CWE-59. Red Hat lists Red Hat Hardened Images as not affected. Red Hat fixing advisory: RHSA-2026:61586, RHSA-2026:61581, RHSA-2026:61783, RHSA-2026:50807. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 9; Red Hat Discovery 2; Red Hat Enterprise Linux 6; and 4 more.
Medium [CVE-2026-68742] NSS responder out-of-bounds read via unchecked addrlen in GETHOSTBYADDR
A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function in the NSS responder does not validate the addrlen field against the remaining packet body size. A local attacker can exploit this via a crafted GETHOSTBYADDR request to the NSS responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service. This issue can only be triggered by a local attacker who can connect to the SSSD NSS responder unix socket and send crafted requests. The over-read bytes are used as a lookup key and are not returned to the client, so the impact is limited to denial of service. The sssd monitor may respawn the responder, but repeated crashes can lead to a persistent name-resolution outage for SSSD-managed users. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Red Hat lists Red Hat Enterprise Linux 6 as not affected. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: sssd.
Medium [CVE-2026-68743] PAM responder out-of-bounds read via unchecked auth_token_length in protocol v1
A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker can exploit this via a crafted protocol v1 request to the PAM responder socket, causing an out-of-bounds read and process crash, resulting in a denial of service. This issue can only be triggered by a local attacker who can connect to the SSSD PAM responder unix socket and send crafted protocol v1 requests. The stock PAM client uses protocol v3 and is not affected by this path. On SSSD 2.10 and later, responders run as an unprivileged user; on earlier versions they may run as root. In either case, the impact is a denial of service of SSSD-mediated authentication. The sssd monitor may respawn the responder, but repeated crashes can lead to a persistent authentication outage for SSSD-managed users. This issue is distinct from CVE-2026-6245, which affects a different code path (pam_passkey_child_read_data). Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H). Weakness: CWE-125. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; Red Hat OpenShift Container Platform 4. Will not fix / out of support: Red Hat Enterprise Linux 6.
Medium [CVE-2026-6695] remote code execution via crafted paa file
A flaw was found in GIMP. A remote attacker could exploit this by tricking a user into opening a specially crafted PAA (Paint Shop Pro Array) image file. This vulnerability, a heap-based out-of-bounds write in the decode_lzss() function of the PAA file format plugin, allows data to be written beyond the intended memory buffer. This could lead to heap metadata corruption and potentially enable the attacker to execute arbitrary code on the affected system. Red Hat Enterprise Linux systems where GIMP is installed and used to process untrusted image files are affected. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-805. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9; and 1 more. Affected products named by the advisory: Red Hat package: gimp.
Medium [CVE-2026-6694] gimp file-png plugin: denial of service via oversized apng trns chunk
A flaw was found in GIMP's file-png plugin. A remote attacker can exploit this by crafting a malicious Animated Portable Network Graphics (APNG) image containing an oversized tRNS chunk. When processing a specially crafted APNG image, the plugin may crash due to a stack buffer overflow. As GIMP executes plugins in separate processes, the main application remains unaffected, limiting the impact to the plugin's functionality. Red Hat severity: Moderate — CVSS 5.5 (CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-120. Affected Red Hat products: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: gimp.
Medium [CVE-2026-67302] Denial of service in camera redirection due to divide-by-zero
FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a divide-by-zero vulnerability in the rdpecam camera redirection client. ecam_dev_process_start_streams_request() parses a server-controlled CAM_MEDIA_TYPE_DESCRIPTION from a StartStreamsRequest PDU but validates only Format and Flags, not FrameRateDenominator. When a malicious or compromised RDP server sends a StartStreamsRequest with FrameRateDenominator set to zero, ecam_encoder_context_init() (channels/rdpecam/client/encoding.c) computes FrameRateNumerator / FrameRateDenominator, causing an integer division by zero (SIGFPE) and termination of the FreeRDP client process. Camera redirection must be enabled on the client for the channel to be reachable. Fixed in FreeRDP 3.29.0. A flaw was found in FreeRDP, a remote desktop protocol client. A malicious or compromised RDP server can exploit this vulnerability by sending a specially crafted `StartStreamsRequest` with a zero value for `FrameRateDenominator`. This vulnerability in FreeRDP affects clients with camera redirection enabled. A malicious RDP server could send a crafted `StartStreamsRequest` PDU, leading to a divide-by-zero error and client process termination, resulting in a denial of service. Exploitation requires user interaction to connect to a compromised server with the vulnerable feature active.
Medium [CVE-2026-67306] Out-of-bounds read vulnerability via crafted RDP messages
FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functions planar_decompress_plane_rle and planar_decompress_plane_rle_only in libfreerdp/codec/planar.c. Only the 1-byte control byte is bounds-checked; the subsequent 0–15 attacker-declared raw bytes are read without validating that the source buffer contains them. A malicious or compromised RDP server can send a truncated planar-encoded bitmap or surface update (reachable via both the Bitmap Update PDU and RDPGFX Surface Command paths) that causes the client to read past the end of the source buffer. A flaw was found in FreeRDP. This can cause the client to read beyond the intended memory buffer, potentially leading to a denial of service (client crash) or the disclosure of sensitive information. Successful exploitation requires user interaction or specific client connection behavior. An attacker cannot trigger this vulnerability remotely on an arbitrary client system without the client actively initiating an RDP session to a malicious or compromised RDP server. The out-of-bounds read vulnerability is strictly contained within the client application process. Affected products named by the advisory: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; and 2 more.
Medium [CVE-2026-67295] Unauthorized File Access via Drive Redirection Vulnerability
FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. A malicious RDP server can read, write, delete, and enumerate files in sibling directories by sending non-rooted paths that bypass the shared-root boundary check. A flaw was found in FreeRDP, an open-source implementation of the Remote Desktop Protocol (RDP). This vulnerability allows a malicious RDP server to bypass security checks during drive redirection. By sending specially crafted paths, the server can access, read, write, delete, and list files in directories outside the intended shared folder on the client's system. This could lead to unauthorized access and manipulation of sensitive data. Red Hat severity: Moderate — CVSS 6.3 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:L). Weakness: CWE-22. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9. Will not fix / out of support: Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7. Red Hat does not currently list a fixing RHSA for this CVE. Affected products named by the advisory: Red Hat package: freerdp.
Medium [CVE-2026-67300] Use-After-Free vulnerability leading to denial of service
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. When a malicious or compromised RDP server sends crafted update orders, the message proxy shallow-copies structures containing nested parser-owned pointers (e.g., titleInfo.string, windowRects, visibilityRects, icon buffers). The parser frees those nested buffers after the callback returns, so the queued async message later dispatches stale pointers, potentially causing memory corruption or a client crash. A flaw was found in FreeRDP. This client-side heap use-after-free vulnerability occurs when a malicious or compromised Remote Desktop Protocol (RDP) server sends specially crafted update orders. The async update message proxy incorrectly handles memory by shallow-copying structures with pointers that are later freed by the parser. This leads to the use of stale pointers, which can cause memory corruption or a client crash, resulting in a denial of service. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H). Weakness: CWE-825. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.
Medium [CVE-2026-67292] Information Disclosure and Denial of Service via WebSocket Ping
FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/core/gateway/websocket.c). The client's Pong reply reuses a fixed 1024-byte response stream whose length is not sealed to the actual received Ping payload, so a malicious gateway/WebSocket peer sending a non-empty Ping control frame causes the client to reply with an overlong Pong that discloses bytes beyond the received payload (the peer receives the masking key and can unmask the reply). A zero-length Ping reaches an assertion and terminates the client (denial of service). A flaw was found in FreeRDP, a remote desktop protocol client. This could cause the client to send an overly long Pong reply, leading to the disclosure of sensitive information beyond the intended payload. This issue is classified as Moderate severity because successful exploitation requires a user to connect to a malicious gateway or server, where a crafted Ping control frame can trigger a client memory disclosure or cause an application crash leading to a denial of service. Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L). Weakness: CWE-805. Affected Red Hat products: Red Hat Enterprise Linux 10; Red Hat Enterprise Linux 6; Red Hat Enterprise Linux 7; Red Hat Enterprise Linux 8; Red Hat Enterprise Linux 9.