PT-2026-57295 · Freerdp+2 · Freerdp+2

CVE-2026-57158

·

Published

2026-07-10

·

Updated

2026-08-10

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions FreeRDP versions 3.21.0 through 3.27.0
Description FreeRDP clients using the GFX pipeline contain an incomplete fix in the planar decompress plane rle only() function within libfreerdp/codec/planar.c. This allows a malicious RDP server to send a truncated RDPGFX CMDID WIRETOSURFACE 1 planar payload, resulting in a read operation that extends one byte beyond the input buffer.
Recommendations Update FreeRDP to version 3.28.0.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57158
GHSA-MP3F-59PG-C5PP
OPENSUSE-SU-2026:11263-1
SUSE-SU-2026:3562-1
USN-8561-1

Affected Products

Freerdp
Linuxmint
Ubuntu