CVE-2023-40184: Improper handling of session establishment errors in xrdp
Last updated 26 June 2026
Other sources
xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The authstartsession function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such as max concurrent sessions per user by PAM (ex ./etc/security/limits.conf) to be bypassed. Users (administrators) don't use restrictions by PAM are not affected. This issue has been addressed in release version 0.9.23. Users are advised to upgrade. There are no known workarounds for this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/xrdpto a version that resolves this vulnerability.Fixed in 0.9.21.1-1~deb11u3Fixed in 0.9.21.1-1+deb12u2Fixed in 0.10.1-3.1+deb13u1Fixed in 0.10.5-5Fixed in 0.10.6-5 - Upgrade
Upgrade
xrdpto a version that resolves this vulnerability.Fixed in 0.9.23
Event History
Frequently Asked Questions
What is CVE-2023-40184?
CVE-2023-40184 is a vulnerability in the xrdp remote desktop protocol (RDP) server that allows bypassing OS-level session restrictions.
How does CVE-2023-40184 affect xrdp?
CVE-2023-40184 affects xrdp versions prior to 0.9.23 and results in improper handling of session establishment errors.
What is the severity of CVE-2023-40184?
CVE-2023-40184 has a severity rating of medium with a CVSS score of 6.5.
How can CVE-2023-40184 be exploited?
CVE-2023-40184 can be exploited by returning a non-zero value on session establishment errors, such as PAM error, to bypass OS-level session restrictions.
How can I fix CVE-2023-40184?
To fix CVE-2023-40184, upgrade xrdp to version 0.9.23 or later.