Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-23531

Опубликовано: 19 янв. 2026
Источник: redhat
CVSS3: 7.6
EPSS Низкий

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when glyphData is present, clear_decompress calls freerdp_image_copy_no_overlap without validating the destination rectangle, allowing an out-of-bounds read/write via crafted RDPGFX surface updates. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue.

A flaw was found in FreeRDP. A malicious server can exploit an out-of-bounds read/write vulnerability in the ClearCodec component by sending crafted RDPGFX surface updates. This can trigger a client-side heap buffer overflow, leading to a crash (Denial of Service (DoS)) and potential heap corruption with a risk of arbitrary code execution. For this vulnerability to be exploited, a client must connect to a maliciously-configured server.

Отчет

For this vulnerability to be exploited, a client must connect to a maliciously-configured server. Red Hat recommends that FreeRDP clients are only used to connect to trusted servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6freerdpWill not fix
Red Hat Enterprise Linux 10freerdpFixedRHSA-2026:222209.02.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportfreerdpFixedRHSA-2026:295218.02.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportfreerdpFixedRHSA-2026:271416.02.2026
Red Hat Enterprise Linux 8freerdpFixedRHSA-2026:208105.02.2026
Red Hat Enterprise Linux 8.2 Advanced Update SupportfreerdpFixedRHSA-2026:303923.02.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportfreerdpFixedRHSA-2026:303823.02.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnfreerdpFixedRHSA-2026:303823.02.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportfreerdpFixedRHSA-2026:303623.02.2026
Red Hat Enterprise Linux 8.6 Telecommunications Update ServicefreerdpFixedRHSA-2026:303623.02.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-122
https://bugzilla.redhat.com/show_bug.cgi?id=2430887freerdp: FreeRDP: Heap buffer overflow via crafted RDPGFX surface updates leads to denial of service and potential code execution.

EPSS

Процентиль: 33%
0.00132
Низкий

7.6 High

CVSS3

Связанные уязвимости

CVSS3: 9.8
ubuntu
2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle, allowing an out-of-bounds read/write via crafted RDPGFX surface updates. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue.

CVSS3: 9.8
nvd
2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle, allowing an out-of-bounds read/write via crafted RDPGFX surface updates. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue.

CVSS3: 9.8
debian
2 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 7.5
fstec
2 месяца назад

Уязвимость функции clear_decompress() RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании

oracle-oval
13 дней назад

ELSA-2026-2714: freerdp security update (IMPORTANT)

EPSS

Процентиль: 33%
0.00132
Низкий

7.6 High

CVSS3