Количество 22
Количество 22
BDU:2026-04141
Уязвимость функции gdi_surface_bits() RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код
ROS-20260624-73-0009
Уязвимость freerdp3
CVE-2026-31806
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP server can supply crafted bmp.width and bmp.height values that exceed the expected surface size. Because these values are used during bitmap decoding and memory operations without proper bounds checking, this can lead to a heap buffer overflow. Since the attacker can also control the associated pixel data transmitted by the server, the overflow may be exploitable to overwrite adjacent heap memory. This vulnerability is fixed in 3.24.0.
CVE-2026-31806
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP server can supply crafted bmp.width and bmp.height values that exceed the expected surface size. Because these values are used during bitmap decoding and memory operations without proper bounds checking, this can lead to a heap buffer overflow. Since the attacker can also control the associated pixel data transmitted by the server, the overflow may be exploitable to overwrite adjacent heap memory. This vulnerability is fixed in 3.24.0.
CVE-2026-31806
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP server can supply crafted bmp.width and bmp.height values that exceed the expected surface size. Because these values are used during bitmap decoding and memory operations without proper bounds checking, this can lead to a heap buffer overflow. Since the attacker can also control the associated pixel data transmitted by the server, the overflow may be exploitable to overwrite adjacent heap memory. This vulnerability is fixed in 3.24.0.
CVE-2026-31806
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...
SUSE-SU-2026:1165-1
Security update for freerdp
SUSE-SU-2026:1164-1
Security update for freerdp2
SUSE-SU-2026:1160-1
Security update for freerdp
SUSE-SU-2026:1129-1
Security update for freerdp
SUSE-SU-2026:1398-1
Security update for freerdp
ELSA-2026-11323
ELSA-2026-11323: freerdp security update (IMPORTANT)
RLSA-2026:6918
Important: freerdp security update
RLSA-2026:6340
Important: freerdp security update
ELSA-2026-6918
ELSA-2026-6918: freerdp security update (IMPORTANT)
ELSA-2026-6340
ELSA-2026-6340: freerdp security update (IMPORTANT)
RLSA-2026:6799
Important: freerdp security update
ELSA-2026-6799
ELSA-2026-6799: freerdp security update (IMPORTANT)
SUSE-SU-2026:1640-1
Security update for freerdp2
openSUSE-SU-2026:20632-1
Security update for freerdp2
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
BDU:2026-04141 Уязвимость функции gdi_surface_bits() RDP-клиента FreeRDP, позволяющая нарушителю выполнить произвольный код | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
ROS-20260624-73-0009 Уязвимость freerdp3 | CVSS3: 8.8 | 1% Низкий | около 1 месяца назад | |
CVE-2026-31806 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP server can supply crafted bmp.width and bmp.height values that exceed the expected surface size. Because these values are used during bitmap decoding and memory operations without proper bounds checking, this can lead to a heap buffer overflow. Since the attacker can also control the associated pixel data transmitted by the server, the overflow may be exploitable to overwrite adjacent heap memory. This vulnerability is fixed in 3.24.0. | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-31806 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP server can supply crafted bmp.width and bmp.height values that exceed the expected surface size. Because these values are used during bitmap decoding and memory operations without proper bounds checking, this can lead to a heap buffer overflow. Since the attacker can also control the associated pixel data transmitted by the server, the overflow may be exploitable to overwrite adjacent heap memory. This vulnerability is fixed in 3.24.0. | CVSS3: 8.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-31806 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP server can supply crafted bmp.width and bmp.height values that exceed the expected surface size. Because these values are used during bitmap decoding and memory operations without proper bounds checking, this can lead to a heap buffer overflow. Since the attacker can also control the associated pixel data transmitted by the server, the overflow may be exploitable to overwrite adjacent heap memory. This vulnerability is fixed in 3.24.0. | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
CVE-2026-31806 FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ... | CVSS3: 9.8 | 1% Низкий | 5 месяцев назад | |
SUSE-SU-2026:1165-1 Security update for freerdp | 4 месяца назад | |||
SUSE-SU-2026:1164-1 Security update for freerdp2 | 4 месяца назад | |||
SUSE-SU-2026:1160-1 Security update for freerdp | 4 месяца назад | |||
SUSE-SU-2026:1129-1 Security update for freerdp | 4 месяца назад | |||
SUSE-SU-2026:1398-1 Security update for freerdp | 4 месяца назад | |||
ELSA-2026-11323 ELSA-2026-11323: freerdp security update (IMPORTANT) | около 2 месяцев назад | |||
RLSA-2026:6918 Important: freerdp security update | 4 месяца назад | |||
RLSA-2026:6340 Important: freerdp security update | 4 месяца назад | |||
ELSA-2026-6918 ELSA-2026-6918: freerdp security update (IMPORTANT) | 4 месяца назад | |||
ELSA-2026-6340 ELSA-2026-6340: freerdp security update (IMPORTANT) | 4 месяца назад | |||
RLSA-2026:6799 Important: freerdp security update | 4 месяца назад | |||
ELSA-2026-6799 ELSA-2026-6799: freerdp security update (IMPORTANT) | 4 месяца назад | |||
SUSE-SU-2026:1640-1 Security update for freerdp2 | 3 месяца назад | |||
openSUSE-SU-2026:20632-1 Security update for freerdp2 | 3 месяца назад |
Уязвимостей на страницу