PT-2026-43250 · Freerdp+3 · Freerdp+3

·

CVE-2026-40033

·

Published

2026-04-21

·

Updated

2026-08-10

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.26.0
Description A heap-buffer-overflow exists in the gdi CacheToSurface() function. This occurs because rectangle validation clamps coordinates to UINT16 MAX but copy operations use unclamped cache entry dimensions. This allows a malicious RDP server to trigger large out-of-bounds writes to heap memory, which could lead to a client crash or remote code execution.
Recommendations Update to version 3.26.0 or later.

Exploit

Fix

RCE

DoS

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36203
BDU:2026-07426
CVE-2026-40033
GHSA-P6R2-4HGM-M6FF
OPENSUSE-SU-2026:10948-1
OPENSUSE-SU-2026:21116-1
RHSA-2026:36203
RHSA-2026:46393
SUSE-SU-2026:22194-1
SUSE-SU-2026:3562-1
USN-8561-1

Affected Products

Freerdp
Linuxmint
Red Os
Ubuntu