Out-of-bounds read in FreeRDP - CVE-2026-55192
Published: June 15, 2026 / Updated: August 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information or cause a denial of service.
The vulnerability exists due to out-of-bounds read in the FreeRDP client H.264 YUV-to-RGB conversion path when processing AVC420 or AVC444 GFX frames from a malicious RDP server with decoder and surface dimension mismatch. A remote attacker can send specially crafted RDP graphics data to disclose sensitive information or cause a denial of service.
Only client-side deployments using libfreerdp GFX H.264 decompression are affected, and exploitation requires RDPGFX with AVC420 or AVC444 negotiated and an H.264 decoder backend enabled.
Affected software
Fedora
freerdp
How to mitigate CVE-2026-55192
freerdp - addressed in versions 3.27.1-1.fc43, 3.27.1-1.fc44