PT-2026-51167 · Freerdp+3 · Freerdp+3
CVE-2026-55827
·
Published
2026-06-19
·
Updated
2026-08-18
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions prior to 3.27.1
Description
When clients are launched with the non-default
/cache:codec:rfx option, the software passes the desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data. However, in the gdi Bitmap Decompress() function, the bitmap->data is allocated only for the smaller DstWidth and DstHeight. This discrepancy allows a malicious RDP server to trigger a heap out-of-bounds write using an attacker-controlled offset and content. A heap out-of-bounds write occurs when a program writes data past the end of a memory buffer allocated on the heap, potentially leading to crashes or arbitrary code execution.Recommendations
Update to version 3.27.1.
As a temporary mitigation, avoid using the
/cache:codec:rfx option when launching clients.Exploit
Fix
DoS
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Freerdp
Linuxmint
Red Os
Ubuntu