Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55194

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 8.8
EPSS Низкий

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.

A flaw was found in FreeRDP. A remote attacker, specifically a malicious TS Gateway, can exploit a heap-buffer-overflow vulnerability by sending a specially crafted Remote Desktop Protocol (RDP) response. This occurs because the client incorrectly uses a smaller alloc_hint value instead of the actual StubLength for buffer capacity during response reassembly. This allows attacker-controlled data to be written beyond the intended buffer, leading to a client crash and potentially enabling arbitrary code execution.

Отчет

A heap buffer overflow flaw was found in FreeRDP's TS Gateway RPC client (libfreerdp/core/gateway/rpc_client.c). During response fragment reassembly in rpc_client_recv_fragment, stream allocation relies on the server-provided alloc_hint rather than the actual StubLength. A malicious TS Gateway can send a PTYPE_RESPONSE packet with a small alloc_hint and a larger payload, causing Stream_Write to overwrite memory beyond the fixed 4096-byte buffer (pdu->s). This can result in client crashes or potential arbitrary code execution.

Меры по смягчению последствий

To mitigate this vulnerability, avoid connecting through untrusted TS Gateways (RD Gateways) or disable gateway parameters (such as omitting /g: in xfreerdp) to force direct RDP connections and bypass RPC response parsing.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 10freerdpFixedRHSA-2026:6137831.08.2026
Red Hat Enterprise Linux 10.0 Extended Update SupportfreerdpFixedRHSA-2026:6870617.09.2026
Red Hat Enterprise Linux 7 Extended Lifecycle SupportfreerdpFixedRHSA-2026:6870717.09.2026
Red Hat Enterprise Linux 8freerdpFixedRHSA-2026:6257102.09.2026
Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update SupportfreerdpFixedRHSA-2026:6585509.09.2026
Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-OnfreerdpFixedRHSA-2026:6585509.09.2026
Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update SupportfreerdpFixedRHSA-2026:6628110.09.2026
Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-OnfreerdpFixedRHSA-2026:6628110.09.2026
Red Hat Enterprise Linux 8.8 Telecommunications Update ServicefreerdpFixedRHSA-2026:6628210.09.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-120
https://bugzilla.redhat.com/show_bug.cgi?id=2519824FreeRDP: FreeRDP: Heap-buffer-overflow allows arbitrary code execution via crafted RPC response

EPSS

Процентиль: 38%
0.00459
Низкий

8.8 High

CVSS3

Связанные уязвимости

ubuntu
около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.

nvd
около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.

debian
около 1 месяца назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 8.8
fstec
3 месяца назад

Уязвимость функции rpc_client_recv_fragment() файла libfreerdp/core/gateway/rpc_client.c RDP-клиента FreeRDP, позволяющая нарушителю вызвать отказ в обслуживании и выполнить произвольный код

CVSS3: 8.8
redos
30 дней назад

Уязвимость freerdp3

EPSS

Процентиль: 38%
0.00459
Низкий

8.8 High

CVSS3