PT-2026-61026 · Xrdp+1 · Xrdp+1

CVE-2026-55645

·

Published

2026-07-08

·

Updated

2026-08-18

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions xrdp versions prior to 0.10.6.1
Description An issue exists in the processing of Client Control PDUs (Protocol Data Units) during the RDP connection sequence. The parser fails to perform sufficient length validation before reading specific data fields from the network stream. A remote, unauthenticated attacker can exploit this by sending a specially crafted, truncated Client Control PDU, leading to out-of-bounds memory reads. This can result in a Denial of Service (DoS) by terminating the process. Because the software typically forks a new process for each connection, a crash is unlikely to affect the entire service.
Recommendations Update to version 0.10.6.1.

Exploit

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-55645
GHSA-3M4M-H22G-C7XX
OPENSUSE-SU-2026:11543-1

Affected Products

Red Os
Xrdp