CVE-2026-25941: FreeRDP: vuln_1_15_1 RDPGFX WIRE_TO_SURFACE_2 Out-of-Bounds Read
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory by sending a crafted WIRETOSURFACE2 PDU with a bitmapDataLength value larger than the actual data in the packet. This can lead to information disclosure or client crashes when a user connects to a malicious server. Versions 2.11.8 and 3.23.0 fix the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-25941?
CVE-2026-25941 has been classified as a medium severity vulnerability due to the potential for unauthorized information disclosure.
How do I fix CVE-2026-25941?
To fix CVE-2026-25941, users should upgrade FreeRDP to version 2.11.8 or 3.23.0 or later.
What versions of FreeRDP are affected by CVE-2026-25941?
FreeRDP versions prior to 2.11.8 on the 2.x branch and prior to 3.23.0 on the 3.x branch are affected by CVE-2026-25941.
What type of vulnerability is CVE-2026-25941?
CVE-2026-25941 is identified as an out-of-bounds read vulnerability that may lead to information leakage.
Is user data at risk with CVE-2026-25941?
Yes, CVE-2026-25941 may expose sensitive user data due to the out-of-bounds read in the RDPGFX channel.