Integer overflow in FreeRDP - CVE-2026-55648
Published: June 15, 2026 / Updated: August 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to cause an out-of-bounds read.
The vulnerability exists due to integer overflow in freerdp_image_copy_from_icon_data() when processing a crafted RAIL icon update PDU. A remote attacker can send a specially crafted icon update with attacker-controlled dimensions and pixel data to cause an out-of-bounds read.
Only FreeRDP-based clients running in RAIL/Remote App mode are affected; desktop mode sessions are not affected.
Affected software
Fedora
freerdp
How to mitigate CVE-2026-55648
freerdp - addressed in versions 3.27.1-1.fc43, 3.27.1-1.fc44