PT-2026-57293 · Freerdp+2 · Freerdp+2

CVE-2026-57156

·

Published

2026-07-10

·

Updated

2026-08-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.28.0
Description FreeRDP clients on 32-bit builds contain an integer overflow in the update read delta points() function within libfreerdp/core/orders.c. This occurs when multiplying an attacker-controlled point count by sizeof(DELTA POINT), which can lead to the allocation of an undersized heap buffer. A malicious RDP peer can exploit this to write beyond the buffer boundaries during initialization.
Recommendations Update to version 3.28.0.

Exploit

Fix

Heap Based Buffer Overflow

Integer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57156
GHSA-V5WF-J8J4-77H7
OPENSUSE-SU-2026:11263-1
SUSE-SU-2026:3562-1
USN-8561-1

Affected Products

Freerdp
Linuxmint
Ubuntu