Heap-based buffer overflow in xrdp - CVE-2026-32624
Published: April 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause a denial of service or modify memory.
The vulnerability exists due to heap-based buffer overflow in logon processing when handling a crafted excessively long username and domain name. A remote attacker can send a crafted excessively long username and domain name to cause a denial of service or modify memory.
Only systems where the domain_user_separator setting is configured in xrdp.ini are vulnerable.
Affected software
Debian Linux
Fedora
xrdp (Debian package)
xrdp
How to mitigate CVE-2026-32624
xrdp (Debian package) - update to 0.10.1-3.1+deb13u2
xrdp - addressed in versions 0.10.6-1.el8, 0.10.6-1.el9, 0.10.6-1.fc42, 0.10.6-1.fc43, 0.10.6-1.fc44