PT-2026-3459 · Freerdp+3 · Freerdp+3

Ehdgks0627

·

Published

2026-01-01

·

Updated

2026-03-18

·

CVE-2026-23534

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.21.0
Description FreeRDP, a free implementation of the Remote Desktop Protocol, contains a client-side heap buffer overflow in the ClearCodec bands decode path. Crafted band coordinates can cause writes beyond the destination surface buffer. A malicious server can trigger this, leading to a crash (Denial of Service) and potential heap corruption, which may result in code execution depending on the allocator and heap layout.
Recommendations Update to version 3.21.0 or later.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

ALSA-2026:2048
ALSA-2026:2081
ALSA-2026:2222
BDU:2026-00659
CVE-2026-23534
GHSA-3FRR-MP8W-4599
MGASA-2026-0046
OESA-2026-1516
OESA-2026-1517
OESA-2026-1518
OESA-2026-1519
OESA-2026-1520
OESA-2026-1521
OPENSUSE-SU-2026:10107-1
OPENSUSE-SU-2026:10176-1
OPENSUSE-SU-2026:20320-1
OPENSUSE-SU-2026:20339-1
RHSA-2026:2048
RHSA-2026:2081
RHSA-2026:2222
RHSA-2026:2736
RHSA-2026:2952
RHSA-2026:3037
SUSE-SU-2026:0345-1
SUSE-SU-2026:0417-1
SUSE-SU-2026:0421-1
SUSE-SU-2026:0449-1
SUSE-SU-2026:0559-1
USN-8004-1
USN-8105-1

Affected Products

Freerdp
Linuxmint
Rocky Linux
Ubuntu