PT-2026-44982 · Freerdp+1 · Freerdp+1

·

CVE-2026-44421

·

Published

2026-05-12

·

Updated

2026-08-10

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.26.0
Description A heap-buffer-overflow write can be triggered in the client when connecting to a malicious RDP server that sends crafted RDPGFX PDUs (Protocol Data Units). The issue occurs in the gdi CacheToSurface() function, which validates a destination rectangle clamped to UINT16 MAX but executes the copy operation using the original cacheEntry->width and cacheEntry->height variables. This results in a large out-of-bounds heap write that may lead to client crashes or remote code execution. This issue is only reachable when the client has RDPGFX enabled.
Recommendations Update to version 3.26.0. As a temporary workaround, disable RDPGFX to minimize the risk of exploitation.

Exploit

Fix

DoS

Heap Based Buffer Overflow

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36203
BDU:2026-07647
CVE-2026-44421
GHSA-P6R2-4HGM-M6FF
OPENSUSE-SU-2026:10948-1
OPENSUSE-SU-2026:21116-1
SUSE-SU-2026:22194-1
SUSE-SU-2026:3562-1
USN-8561-1

Affected Products

Freerdp
Red Os