Out-of-bounds read in xrdp - CVE-2026-33689
Published: April 17, 2026
xrdp
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.
The vulnerability exists due to out-of-bounds read in the dynamic channel parser when processing a specially crafted sequence of packets during the initial connection phase. A remote attacker can send a specially crafted sequence of packets to disclose sensitive information or cause a denial of service.
The issue is reachable before authentication during RDP message parsing.