Out-of-bounds write in FreeRDP - CVE-2026-55827

 

Out-of-bounds write in FreeRDP - CVE-2026-55827

Published: June 17, 2026


Vulnerability identifier: #VU134735
CSH Severity: Medium
CVSS v4: 7.1 [CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55827
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to out-of-bounds write in FreeRDP RemoteFX (RFX) Cache Bitmap V3 decode in gdi_Bitmap_Decompress when processing a Cache Bitmap V3 secondary drawing order from an RDP server with codecID=0x03. A remote attacker can send a specially crafted RDP response to execute arbitrary code.

User interaction is required because the victim must connect to the malicious or compromised RDP server. The issue is reachable only after connection is established and only when the non-default /cache:codec:rfx client flag is enabled.


Affected software

FreeRDP
Red Hat Enterprise Linux for x86_64
Red Hat Enterprise Linux for IBM z Systems
Red Hat Enterprise Linux for Power, little endian
Red Hat Enterprise Linux for ARM 64
Red Hat Enterprise Linux for x86_64 - Extended Update Support
Red Hat Enterprise Linux for IBM z Systems - Extended Update Support
Red Hat Enterprise Linux for Power, little endian - Extended Update Support
Red Hat Enterprise Linux for ARM 64 - Extended Update Support
Red Hat CodeReady Linux Builder for x86_64 - Extended Update Support
Red Hat CodeReady Linux Builder for Power, little endian - Extended Update Support
Red Hat CodeReady Linux Builder for IBM z Systems - Extended Update Support
Red Hat CodeReady Linux Builder for ARM 64 - Extended Update Support
Fedora
freerdp (Red Hat package)
freerdp

How to mitigate CVE-2026-55827

Install security update from vendor's website.

FreeRDP - update to 3.27.1
freerdp (Red Hat package) - addressed in versions 3.10.3-3.el10_0.10, 3.10.3-12.el10_2.7
freerdp - addressed in versions 3.27.1-1.fc43, 3.27.1-1.fc44

External References

Related Security Bulletins