Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-55648

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 4.3

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-bit arithmetic. A malicious RDP server can send a RAIL TS_ICON_INFO update with dimensions such as 32768 by 32768 and 32 bits per pixel so the required-size calculation wraps, bypassing the cbBitsColor source bounds check before freerdp_image_copy_no_overlap reads attacker-controlled icon data. This affects RemoteApp clients using the vulnerable library path, while xfreerdp has a caller-side mitigation. This issue is fixed in version 3.27.0.

A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. An integer overflow vulnerability in the freerdp_image_copy_from_icon_data function allows a malicious Remote Desktop Protocol (RDP) server to bypass a bounds check. By sending a specially crafted icon update with large dimensions, the server can cause the client to read attacker-controlled data beyond the intended memory buffer. This out-of-bounds read can lead to information disclosure or potentially arbitrary code execution on affected RemoteApp clients.

Меры по смягчению последствий

The vulnerability requires a client to connect to a malicious RDP server. To mitigate this risk, users should avoid connecting to untrusted or unknown RDP servers. Restricting network access to only known and trusted RDP servers can also reduce the attack surface.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpFix deferred
Red Hat Enterprise Linux 6freerdpOut of support scope
Red Hat Enterprise Linux 7freerdpFix deferred
Red Hat Enterprise Linux 8freerdpFix deferred
Red Hat Enterprise Linux 9freerdpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2519816FreeRDP: FreeRDP: Integer overflow allows out-of-bounds read via malicious RDP server

4.3 Medium

CVSS3

Связанные уязвимости

ubuntu
2 месяца назад

Integer Overflow in `freerdp_image_copy_from_icon_data` Bypasses Bounds Check

nvd
28 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-bit arithmetic. A malicious RDP server can send a RAIL TS_ICON_INFO update with dimensions such as 32768 by 32768 and 32 bits per pixel so the required-size calculation wraps, bypassing the cbBitsColor source bounds check before freerdp_image_copy_no_overlap reads attacker-controlled icon data. This affects RemoteApp clients using the vulnerable library path, while xfreerdp has a caller-side mitigation. This issue is fixed in version 3.27.0.

debian
28 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

CVSS3: 9.1
redos
23 дня назад

Уязвимость freerdp3

CVSS3: 9.1
redos
23 дня назад

Уязвимость freerdp3

4.3 Medium

CVSS3