PT-2026-44989 · Freerdp+1 · Freerdp+1

Kevin-Valerio

·

Published

2026-05-29

·

Updated

2026-06-16

·

CVE-2026-45700

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.26.0
Description The planar bitmap decoder contains an out-of-bounds heap write when decoding RLE planar data. In the libfreerdp/codec/planar.c file, the freerdp bitmap decompress planar() function validates the X destination coordinate nXDst against the caller-provided destination stride nDstStep while writing into the internal temporary buffer pTempData. An attacker can bypass this check by using a large nDstStep and a large nXDst, which causes the planar decompress plane rle() function to write past the end of pTempData.
Recommendations Update to version 3.26.0.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-45700
OPENSUSE-SU-2026:10948-1
USN-8432-1

Affected Products

Freerdp
Ubuntu