Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55192

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 decoder backends can return YUV planes sized from the bitstream without comparing the decoded width and height to the RDPGFX surface dimensions used to validate region rectangles. A malicious RDP server can provide an AVC420 or AVC444 bitstream whose decoded frame is smaller than the negotiated surface, causing yuv420_context_decode and the YUV-to-RGB conversion paths to read beyond the decoder-owned planes in libfreerdp/codec/h264.c and the selected H.264 backend. This can disclose client memory or crash the client. This issue is fixed in version 3.27.0.

A flaw was found in FreeRDP. A malicious Remote Desktop Protocol (RDP) server can provide a specially crafted H.264 video stream that causes the client's H.264 decoder to read beyond its allocated memory. This out-of-bounds read can lead to the disclosure of sensitive client memory or cause the client application to crash, resulting in a denial of service.

Отчет

An out-of-bounds memory read flaw was found in FreeRDP's H.264 video decoder (libfreerdp/codec/h264.c). When handling AVC420 or AVC444 bitstreams, decoder backends fail to validate frame dimensions against negotiated RDPGFX surface boundaries. A malicious RDP server can send a video frame smaller than the surface, causing yuv420_context_decode and YUV-to-RGB conversion paths to read past allocated memory buffers. This allows an untrusted server to exfiltrate sensitive client memory contents or crash the client application.

Меры по смягчению последствий

To mitigate this vulnerability, disable H.264 graphics acceleration in client connection parameters (e.g., omitting /gfx:avc420 or /gfx:avc444 in xfreerdp) to force legacy RemoteFX or standard software bitmap rendering.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 8freerdpNot affected
Red Hat Enterprise Linux 9freerdpAffected
Red Hat Enterprise Linux 10.0 Extended Update SupportfreerdpFixedRHSA-2026:6870617.09.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportfreerdpFixedRHSA-2026:6870717.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2519823FreeRDP: FreeRDP: Out-of-bounds read leads to memory disclosure or client crash

EPSS

Процентиль: 42%
0.00498
Низкий

8.1 High

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 decoder backends can return YUV planes sized from the bitstream without comparing the decoded width and height to the RDPGFX surface dimensions used to validate region rectangles. A malicious RDP server can provide an AVC420 or AVC444 bitstream whose decoded frame is smaller than the negotiated surface, causing yuv420_context_decode and the YUV-to-RGB conversion paths to read beyond the decoder-owned planes in libfreerdp/codec/h264.c and the selected H.264 backend. This can disclose client memory or crash the client. This issue is fixed in version 3.27.0.

nvd
около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP H.264 decoder backends can return YUV planes sized from the bitstream without comparing the decoded width and height to the RDPGFX surface dimensions used to validate region rectangles. A malicious RDP server can provide an AVC420 or AVC444 bitstream whose decoded frame is smaller than the negotiated surface, causing yuv420_context_decode and the YUV-to-RGB conversion paths to read beyond the decoder-owned planes in libfreerdp/codec/h264.c and the selected H.264 backend. This can disclose client memory or crash the client. This issue is fixed in version 3.27.0.

debian
около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 8.1
fstec
3 месяца назад

Уязвимость файла libfreerdp/codec/h264.c подсистемы декомпрессии H.264 RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании и раскрыть защищаемую информацию

CVSS3: 8.1
redos
30 дней назад

Уязвимость freerdp3

EPSS

Процентиль: 42%
0.00498
Низкий

8.1 High

CVSS3

Уязвимость CVE-2026-55192