ID:12940 - Exploit for Out-of-bounds read in FreeRDP - CVE-2026-57158

 
Main Vulnerability Database Exploits ID:12940 - Exploit for Out-of-bounds read in FreeRDP - CVE-2026-57158

ID:12940 - Exploit for Out-of-bounds read in FreeRDP - CVE-2026-57158

Published: August 21, 2026


Vulnerability identifier: #VU136925
Vulnerability risk: Medium
CVE-ID: CVE-2026-57158
CWE-ID: CWE-125
Exploitation vector: Remote access
Vulnerable software:
FreeRDP
Fedora
freerdp

Link to public exploit:


Vulnerability description

The vulnerability allows a remote attacker to cause a denial of service.

The vulnerability exists due to out-of-bounds read in planar_decompress_plane_rle_only when processing a truncated RLE planar payload in RDPGFX_CMDID_WIRETOSURFACE_1. A remote attacker can send a specially crafted WireToSurface packet with codecId=PLANAR and a payload truncated by 1 byte to cause a denial of service.

No user interaction beyond connecting to the server is required.


Remediation

Install security update from vendor's website.