Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-69159

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 5.4

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.29.0, planar_decompress_plane_rle and planar_decompress_plane_rle_only in libfreerdp/codec/planar.c verify that a control byte exists but do not verify that the source buffer contains the zero to fifteen raw bytes declared by that control byte. A malicious RDP server can send a truncated planar bitmap or surface update whose final control byte claims additional raw bytes, causing the decoder to read beyond pSrcData while processing a color plane. This can crash the client and may disclose adjacent memory. This issue is fixed in version 3.29.0.

A flaw was found in FreeRDP, an implementation of the Remote Desktop Protocol. A malicious RDP server can exploit an out-of-bounds read vulnerability by sending a malformed planar bitmap or surface update. This causes the client's decoder to read beyond its allocated buffer, which can lead to a client crash, resulting in a denial of service. Additionally, this flaw may disclose sensitive information from adjacent memory.

Отчет

An out-of-bounds read vulnerability was found in FreeRDP's planar bitmap decoder (libfreerdp/codec/planar.c). Functions planar_decompress_plane_rle and planar_decompress_plane_rle_only fail to verify that the source buffer contains the required raw bytes specified by a control byte. A malicious RDP server can send a truncated planar bitmap or surface update claiming additional raw bytes, causing the client to read past the source buffer boundary. This can lead to a client application crash or partial disclosure of adjacent client memory.

Меры по смягчению последствий

To mitigate this vulnerability, disable RDP planar graphics codec acceleration in client settings or force alternative graphics rendering modes (such as standard RemoteFX or H.264) when connecting to untrusted RDP servers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpAffected
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpFix deferred
Red Hat Enterprise Linux 8freerdpFix deferred
Red Hat Enterprise Linux 9freerdpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-125
https://bugzilla.redhat.com/show_bug.cgi?id=2519828FreeRDP: FreeRDP: Out-of-bounds read leads to denial of service and information disclosure

5.4 Medium

CVSS3

Связанные уязвимости

ubuntu
12 дней назад

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67306. Reason: This candidate is a duplicate of CVE-2026-67306. Notes: All CVE users should reference CVE-2026-67306 instead of this candidate.

nvd
12 дней назад

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-67306. Reason: This candidate is a duplicate of CVE-2026-67306. Notes: All CVE users should reference CVE-2026-67306 instead of this candidate.

5.4 Medium

CVSS3