Out-of-bounds read in FreeRDP - #VU146589
Published: September 1, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and cause a denial of service.
The vulnerability exists due to out-of-bounds read in general_ChromaV1ToYUV444 in the FreeRDP primitives library when processing a crafted RFX_AVC444_BITMAP_STREAM from a malicious server. A remote attacker can send a specially crafted bitmap stream to disclose sensitive information and cause a denial of service.
User interaction is required because the victim must connect to the malicious RDP server. The issue affects the server-to-client direction and is duplicated in the generic, NEON, and SSE implementations.