Out-of-bounds read in xrdp - CVE-2026-55639

 

Out-of-bounds read in xrdp - CVE-2026-55639

Published: July 2, 2026


Vulnerability identifier: #VU136783
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-55639
CWE-ID: CWE-125
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information.

The vulnerability exists due to out-of-bounds read in the Client Security Data parser when parsing the Client MCS Connect Initial PDU with GCC Conference Create Request during the connection sequence. A remote attacker can send a specially crafted RDP packet containing malformed data to disclose sensitive information.

The issue may read a small number of bytes beyond the declared data block boundary during the initial capability and security negotiation phase.


Affected software

xrdp
Debian Linux
Fedora
xrdp (Debian package)
xrdp

How to mitigate CVE-2026-55639

Install security update from vendor's website.

xrdp - update to 0.10.6.1
xrdp (Debian package) - update to 0.10.1-3.1+deb13u2
xrdp - addressed in versions 0.10.6.1-1.el8, 0.10.6.1-1.el9, 0.10.6.1-1.fc43, 0.10.6.1-1.fc44

External References

Related Security Bulletins