Out-of-bounds write in FreeRDP - CVE-2026-55827
Published: June 17, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code.
The vulnerability exists due to out-of-bounds write in FreeRDP RemoteFX (RFX) Cache Bitmap V3 decode in gdi_Bitmap_Decompress when processing a Cache Bitmap V3 secondary drawing order from an RDP server with codecID=0x03. A remote attacker can send a specially crafted RDP response to execute arbitrary code.
User interaction is required because the victim must connect to the malicious or compromised RDP server. The issue is reachable only after connection is established and only when the non-default /cache:codec:rfx client flag is enabled.
Affected software
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Fedora
freerdp (Red Hat package)
freerdp
How to mitigate CVE-2026-55827
freerdp (Red Hat package) - addressed in versions 3.10.3-3.el10_0.10, 3.10.3-12.el10_2.7
freerdp - addressed in versions 3.27.1-1.fc43, 3.27.1-1.fc44