PT-2026-2935 · Freerdp+3 · Freerdp+3

Ehdgks0627

·

Published

2026-01-01

·

Updated

2026-04-06

·

CVE-2026-22855

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.20.1
Description FreeRDP is a free implementation of the Remote Desktop Protocol. A heap out-of-bounds read occurs in the smartcard SetAttrib path when the cbAttrLen variable does not match the actual NDR buffer length.
Recommendations Update to version 3.20.1 or later.

Exploit

Fix

DoS

RCE

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALSA-2026:3067
ALSA-2026:3068
ALSA-2026:3334
BDU:2026-00618
CVE-2026-22855
GHSA-RWP3-G84R-6MX9
MGASA-2026-0086
OESA-2026-1516
OESA-2026-1517
OESA-2026-1518
OESA-2026-1519
OESA-2026-1520
OESA-2026-1521
OPENSUSE-SU-2026:10059-1
OPENSUSE-SU-2026:10459-1
OPENSUSE-SU-2026:20339-1
OPENSUSE-SU-2026:20632-1
RHSA-2026:3067
RHSA-2026:3068
RHSA-2026:3334
RHSA-2026:3975
RHSA-2026:4121
RHSA-2026:4437
RHSA-2026:4438
RHSA-2026:4439
RHSA-2026:4440
RHSA-2026:4446
RHSA-2026:4471
RHSA-2026:4489
SUSE-SU-2026:0345-1
SUSE-SU-2026:0656-1
SUSE-SU-2026:0683-1
SUSE-SU-2026:0761-1
SUSE-SU-2026:0762-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Rocky Linux
Ubuntu