PT-2026-3457 · Freerdp+4 · Freerdp+4

·

CVE-2026-23532

·

Published

2026-01-01

·

Updated

2026-06-30

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.21.0
Description A client-side heap buffer overflow exists in the FreeRDP client’s gdi SurfaceToSurface path. This occurs due to a mismatch between destination rectangle clamping and the actual copy size. A malicious server can trigger this overflow, potentially leading to a crash (Denial of Service) and possible heap corruption, which could result in code execution depending on the allocator and heap layout. The vulnerable component is the gdi SurfaceToSurface function.
Recommendations Update to version 3.21.0 or later.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:2048
ALSA-2026:2081
ALSA-2026:2222
BDU:2026-00657
CVE-2026-23532
GHSA-FQ8C-87HJ-7GVR
MGASA-2026-0046
OESA-2026-1516
OESA-2026-1517
OESA-2026-1518
OESA-2026-1519
OESA-2026-1520
OESA-2026-1521
OPENSUSE-SU-2026:10107-1
OPENSUSE-SU-2026:10176-1
OPENSUSE-SU-2026:20320-1
OPENSUSE-SU-2026:20339-1
RHSA-2026:2048
RHSA-2026:2081
RHSA-2026:2222
RHSA-2026:2714
RHSA-2026:2736
RHSA-2026:2770
RHSA-2026:2824
RHSA-2026:2952
RHSA-2026:3036
RHSA-2026:3037
RHSA-2026:3038
RHSA-2026:3039
RHSA-2026:3041
SUSE-SU-2026:0345-1
SUSE-SU-2026:0417-1
SUSE-SU-2026:0421-1
SUSE-SU-2026:0449-1
SUSE-SU-2026:0559-1
USN-8004-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Red Os
Rocky Linux
Ubuntu