PT-2026-22003 · Freerdp+3 · Freerdp+3

Pavelkohout396

·

Published

2026-01-01

·

Updated

2026-06-09

·

CVE-2026-25941

CVSS v2.0

9.4

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 2.11.8 FreeRDP versions prior to 3.23.0
Description FreeRDP, a free implementation of the Remote Desktop Protocol, contains an out-of-bounds read issue in the FreeRDP client’s RDPGFX channel. A malicious RDP server can exploit this by sending a crafted WIRE TO SURFACE 2 Protocol Data Unit (PDU) with a bitmapDataLength value exceeding the actual data within the packet. This can result in information disclosure or client crashes when a user connects to a malicious server. The vulnerability occurs when reading uninitialized heap memory.
Recommendations Update to FreeRDP version 2.11.8 or later. Update to FreeRDP version 3.23.0 or later.

Exploit

Fix

DoS

Out of bounds Read

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-04136
CVE-2026-25941
GHSA-3546-X645-5CF8
OESA-2026-1516
OESA-2026-1517
OESA-2026-1518
OESA-2026-1519
OESA-2026-1520
OESA-2026-1521
OPENSUSE-SU-2026:10408-1
OPENSUSE-SU-2026:10611-1
OPENSUSE-SU-2026:20632-1
OPENSUSE-SU-2026:20657-1
SUSE-SU-2026:1632-1
SUSE-SU-2026:1633-1
SUSE-SU-2026:1634-1
SUSE-SU-2026:1635-1
SUSE-SU-2026:1640-1
SUSE-SU-2026:21436-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Red Os
Ubuntu