PT-2026-51167 · Freerdp+3 · Freerdp+3

CVE-2026-55827

·

Published

2026-06-19

·

Updated

2026-08-18

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.27.1
Description When clients are launched with the non-default /cache:codec:rfx option, the software passes the desktop stride and height to RemoteFX decoding for Cache Bitmap V3 data. However, in the gdi Bitmap Decompress() function, the bitmap->data is allocated only for the smaller DstWidth and DstHeight. This discrepancy allows a malicious RDP server to trigger a heap out-of-bounds write using an attacker-controlled offset and content. A heap out-of-bounds write occurs when a program writes data past the end of a memory buffer allocated on the heap, potentially leading to crashes or arbitrary code execution.
Recommendations Update to version 3.27.1. As a temporary mitigation, avoid using the /cache:codec:rfx option when launching clients.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:50747
CVE-2026-55827
GHSA-C495-H83V-3PRP
OPENSUSE-SU-2026:11065-1
RHSA-2026:50747
RHSA-2026:54667
USN-8561-1

Affected Products

Freerdp
Linuxmint
Red Os
Ubuntu