CVE-2026-26955: FreeRDP has Out-of-bounds Write

Published Feb 25, 2026
·
Updated

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., xfreerdp) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The gdiSurfaceCommandClearCodec() handler does not call iswithinsurface() to validate the command rectangle against the destination surface dimensions, allowing attacker-controlled cmd->left/cmd->top (and subcodec rectangle offsets) to reach image copy routines that write into surface->data without bounds enforcement. The OOB write corrupts an adjacent gdiGfxSurface struct's codecs pointer with attacker-controlled pixel data, and corruption of codecs is sufficient to reach an indirect function pointer call (NSCCONTEXT.decode at nsc.c:500) on a subsequent codec command — full instruction pointer (RIP) control demonstrated in exploitability harness. Users should upgrade to version 3.23.0 to receive a patch.

Affected Software

2 affected components
FreeRDP freerdp<3.23.0
FreeRDP freerdp<3.23.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FreeRDP to a version that resolves this vulnerability.

    Fixed in 3.23.0

Event History

Feb 25, 2026
CVE Published
via MITRE·08:47 PM
Data Sourced
via MITRE·08:47 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 26, 2026
Data Sourced
via Red Hat·09:04 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-26955?

CVE-2026-26955 has a high severity due to its potential to cause a heap buffer overflow that can be exploited by malicious RDP servers.

2

How do I fix CVE-2026-26955?

To fix CVE-2026-26955, upgrade FreeRDP to version 3.23.0 or later.

3

What are the affected versions of FreeRDP for CVE-2026-26955?

FreeRDP versions prior to 3.23.0 are affected by CVE-2026-26955.

4

What impact does CVE-2026-26955 have on FreeRDP clients?

CVE-2026-26955 can lead to a heap buffer overflow in FreeRDP clients, potentially allowing remote code execution.

5

Is CVE-2026-26955 related to the Remote Desktop Protocol?

Yes, CVE-2026-26955 is directly related to the Remote Desktop Protocol as it affects FreeRDP, an implementation of this protocol.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203