PT-2026-78560 · Freerdp · Freerdp

CVE-2026-69159

·

Published

2026-08-19

·

Updated

2026-08-31

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Name of the Vulnerable Software and Affected Versions FreeRDP versions prior to 3.29.0
Description In the libfreerdp/codec/planar.c file, the functions planar decompress plane rle() and planar decompress plane rle only() verify the existence of a control byte but fail to confirm if the source buffer contains the raw bytes declared by that byte. A malicious RDP server can send a truncated planar bitmap or surface update where the final control byte claims additional raw bytes, leading the decoder to read beyond the pSrcData variable while processing a color plane. This can result in a client crash or the disclosure of adjacent memory.
Recommendations Update to version 3.29.0.

Exploit

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:61378
CVE-2026-69159
GHSA-QRXX-7G3C-J6W3

Affected Products

Freerdp