Heap-based buffer overflow in FreeRDP - CVE-2026-55191
Published: June 15, 2026 / Updated: August 21, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to a heap-based buffer overflow caused by integer overflow in avc444_ensure_buffer in libfreerdp/codec/h264.c when decoding AVC444 GFX frames from a malicious RDP server. A remote attacker can send crafted surface dimensions and H.264 bitstream content to execute arbitrary code.
Exploitation requires a FreeRDP client build using libfreerdp AVC444 decompression with RDPGFX AVC444 negotiated and an H.264 decoder backend enabled.
Affected software
Fedora
freerdp
How to mitigate CVE-2026-55191
freerdp - addressed in versions 3.27.1-1.fc43, 3.27.1-1.fc44