PT-2026-57295 · Freerdp+2 · Freerdp+2
CVE-2026-57158
·
Published
2026-07-10
·
Updated
2026-08-10
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
FreeRDP versions 3.21.0 through 3.27.0
Description
FreeRDP clients using the GFX pipeline contain an incomplete fix in the
planar decompress plane rle only() function within libfreerdp/codec/planar.c. This allows a malicious RDP server to send a truncated RDPGFX CMDID WIRETOSURFACE 1 planar payload, resulting in a read operation that extends one byte beyond the input buffer.Recommendations
Update FreeRDP to version 3.28.0.
Exploit
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freerdp
Linuxmint
Ubuntu