PT-2026-3455 · Freerdp+3 · Freerdp+3

Ehdgks0627

·

Published

2026-01-01

·

Updated

2026-03-18

·

CVE-2026-23530

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.21.0
Description FreeRDP is a free implementation of the Remote Desktop Protocol. The freerdp bitmap decompress planar function does not properly validate the nSrcWidth and nSrcHeight parameters against planar->maxWidth and maxHeight before performing RLE decode. This can lead to a heap buffer overflow on the client-side if a malicious server provides crafted data. This overflow can cause a denial of service (DoS) and potentially allow for code execution, depending on the heap allocator and its surrounding layout. The vulnerable parameters are nSrcWidth and nSrcHeight.
Recommendations Update to version 3.21.0 or later.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2026:2048
ALSA-2026:2081
ALSA-2026:2222
BDU:2026-00655
CVE-2026-23530
GHSA-R4HV-852M-FQ7P
MGASA-2026-0046
OESA-2026-1516
OESA-2026-1517
OESA-2026-1518
OESA-2026-1519
OESA-2026-1520
OESA-2026-1521
OPENSUSE-SU-2026:10107-1
OPENSUSE-SU-2026:10176-1
OPENSUSE-SU-2026:20320-1
OPENSUSE-SU-2026:20339-1
RHSA-2026:2048
RHSA-2026:2081
RHSA-2026:2222
RHSA-2026:2714
RHSA-2026:2736
RHSA-2026:2770
RHSA-2026:2824
RHSA-2026:2952
RHSA-2026:3036
RHSA-2026:3037
RHSA-2026:3038
RHSA-2026:3039
RHSA-2026:3041
SUSE-SU-2026:0345-1
SUSE-SU-2026:0417-1
SUSE-SU-2026:0421-1
SUSE-SU-2026:0449-1
SUSE-SU-2026:0559-1
USN-8004-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Rocky Linux
Ubuntu