CVE-2026-72745

critical Red Hat
CVSS v3 Base Score
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Characteristics
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Confidentiality
High
Integrity
High
Availability
High
Published: August 11, 2026 (26 days ago)
Last Modified: August 11, 2026
Vendor: Red Hat
Source: REDHAT

Description

A flaw was found in FreeRDP. A malicious peer, either a server or client, can exploit an out-of-bounds vulnerability during CredSSP/NLA authentication. By supplying a large 'extra count' (EC) value in a Kerberos GSS Wrap token, an attacker can cause the decryption operation to access memory outside of its intended buffer. This can lead to information disclosure, memory corruption, or a denial of service.

CWE

CWE-823

Affected Products

Red Hat Enterprise Linux 10Red Hat Enterprise Linux 6Red Hat Enterprise Linux 7Red Hat Enterprise Linux 8Red Hat Enterprise Linux 9

References