Integer overflow in FreeRDP - #VU134504
Published: June 15, 2026
FreeRDP
Detailed vulnerability description
The vulnerability allows a remote attacker to cause an out-of-bounds read.
The vulnerability exists due to integer overflow in freerdp_image_copy_from_icon_data() when processing a crafted RAIL icon update PDU. A remote attacker can send a specially crafted icon update with attacker-controlled dimensions and pixel data to cause an out-of-bounds read.
Only FreeRDP-based clients running in RAIL/Remote App mode are affected; desktop mode sessions are not affected.