Heap-based buffer overflow in FreeRDP - CVE-2026-55194

 

Heap-based buffer overflow in FreeRDP - CVE-2026-55194

Published: June 15, 2026 / Updated: August 21, 2026


Vulnerability identifier: #VU134505
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55194
CWE-ID: CWE-122
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code or cause a denial of service.

The vulnerability exists due to heap-based buffer overflow in rpc_client_recv_fragment() in the TS Gateway RPC response reassembly logic when processing a crafted PTYPE_RESPONSE PDU on the RPC OUT channel after gateway negotiation. A remote attacker can send a specially crafted gateway response with a small alloc_hint and oversized stub data to execute arbitrary code or cause a denial of service.

Only FreeRDP clients using TS Gateway / RD Gateway transport are affected; direct RDP connections without the gateway RPC layer are not affected. In default builds the issue may abort via an assertion, while release builds without assertion enforcement may permit exploitation.


Affected software

FreeRDP
Red Hat Enterprise Linux for ARM 64
Anolis OS
Red Hat CodeReady Linux Builder for IBM z Systems
Red Hat CodeReady Linux Builder for ARM 64
Red Hat CodeReady Linux Builder for Power, little endian
Red Hat CodeReady Linux Builder for x86_64
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux Server - AUS
Red Hat Enterprise Linux Server - TUS
Fedora
Red Hat Enterprise Linux Server for Power LE - Update Services for SAP Solutions
freerdp (Red Hat package)
freerdp
freerdp-devel
freerdp-libs
libwinpr
libwinpr-devel
freerdp-doc

How to mitigate CVE-2026-55194

Install security update from vendor's website.

FreeRDP - update to 3.27.0
freerdp (Red Hat package) - addressed in versions 2.2.0-7.el8_6.12, 2.2.0-12.el8_8.11, 2.2.0-14.el8_4.3, 2.4.1-6.el9_2.12, 2.11.2-1.el9_4.11, 2.11.7-7.el9_8.6, 2.11.7-12.el8_10
freerdp - update to 2.11.7-12.0.1
freerdp-devel - update to 2.11.7-12.0.1
freerdp-libs - update to 2.11.7-12.0.1
libwinpr - update to 2.11.7-12.0.1
libwinpr-devel - update to 2.11.7-12.0.1
freerdp-doc - update to 2.11.7-12.0.1
freerdp - addressed in versions 3.27.1-1.fc43, 3.27.1-1.fc44

External References

Related Security Bulletins