PT-2026-44989 · Freerdp+4 · Freerdp+4

·

CVE-2026-45700

·

Published

2026-05-12

·

Updated

2026-08-10

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.26.0
Description The planar bitmap decoder contains an out-of-bounds heap write when decoding RLE planar data. In the libfreerdp/codec/planar.c file, the freerdp bitmap decompress planar() function validates the X destination coordinate nXDst against the caller-provided destination stride nDstStep while writing into the internal temporary buffer pTempData. An attacker can bypass this check by using a large nDstStep and a large nXDst, which causes the planar decompress plane rle() function to write past the end of pTempData.
Recommendations Update to version 3.26.0.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:36203
ALSA-2026:37207
ALSA-2026:38501
BDU:2026-10466
CVE-2026-45700
GHSA-MPXH-8FQ3-X8MH
OPENSUSE-SU-2026:10948-1
OPENSUSE-SU-2026:21116-1
RHSA-2026:37207
RHSA-2026:38501
RHSA-2026:46383
RHSA-2026:46384
RHSA-2026:46388
RHSA-2026:46389
RHSA-2026:47048
RHSA-2026:47049
RHSA-2026:47201
SUSE-SU-2026:22194-1
SUSE-SU-2026:3562-1
USN-8432-1

Affected Products

Freerdp
Linuxmint
Red Os
Rocky Linux
Ubuntu