Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-40033

Опубликовано: 26 мая 2026
Источник: redhat
CVSS3: 8.8

Описание

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

A flaw was found in FreeRDP.If a user connects to a malicious Remote Desktop (RDP) server, a security flaw in FreeRDP could cause the application to crash or allow the server to run unauthorized code on the user's system.

Отчет

This vulnerability in FreeRDP could allow a malicious Remote Desktop server to run unauthorized code or crash the connecting user's system. Red Hat users are only at risk if they use the FreeRDP client to connect to an untrusted or compromised server.

Меры по смягчению последствий

To mitigate this issue, users should avoid connecting to untrusted or unknown Remote Desktop Protocol (RDP) servers. Restricting FreeRDP client usage to only known and trusted RDP servers can reduce the risk of exploitation.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpNot affected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpWill not fix
Red Hat Enterprise Linux 10freerdpFixedRHSA-2026:3620307.07.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportfreerdpFixedRHSA-2026:4639327.07.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-787
https://bugzilla.redhat.com/show_bug.cgi?id=2481473freerdp: FreeRDP: Remote code execution via heap-buffer-overflow in gdi_CacheToSurface

8.8 High

CVSS3

Связанные уязвимости

CVSS3: 8.8
ubuntu
2 месяца назад

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

CVSS3: 8.8
nvd
2 месяца назад

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

CVSS3: 8.8
debian
2 месяца назад

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in ...

CVSS3: 8.8
github
2 месяца назад

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.

CVSS3: 8.8
fstec
3 месяца назад

Уязвимость функции gdi_CacheToSurface() RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код и вызвать отказ в обслуживании

8.8 High

CVSS3