PT-2026-82093 · Rustdesk · Rustdesk
CVE-2026-73108
·
Published
2026-08-26
·
Updated
2026-08-30
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
RustDesk versions prior to 1.4.7
Description
An uncontrolled speculative memory allocation issue exists in the
BytesCodec component. Before authentication, the decoder trusts the payload length specified in a four-byte frame header and reserves that memory before the payload is actually received. An unauthenticated attacker can send a crafted header requesting up to 1,073,741,823 bytes of capacity. By using concurrent TCP connections, this can lead to memory exhaustion and a denial of service.Recommendations
Update RustDesk to version 1.4.7 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rustdesk