CVE-2026-26965: FreeRDP has Out-of-bounds Write

Published Feb 25, 2026
·
Updated

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path, planardecompressplanerle() writes into pDstData at ((nYDst+y) nDstStep) + (4nXDst) + nChannel without verifying that (nYDst+nSrcHeight) fits in the destination height or that (nXDst+nSrcWidth) fits in the destination stride. When TempFormat != DstFormat, pDstData becomes planar->pTempData (sized for the desktop), while nYDst is only validated against the surface by iswithinsurface(). A malicious RDP server can exploit this to perform a heap out-of-bounds write with attacker-controlled offset and pixel data on any connecting FreeRDP client. The OOB write reaches up to 132,096 bytes past the temp buffer end, and on the brk heap (desktop ≤ 128×128), an adjacent NSCCONTEXT struct's decode function pointer is overwritten with attacker-controlled pixel data — control-flow–relevant corruption (function pointer overwritten) demonstrated under deterministic heap layout (nsc->decode = 0xFF414141FF414141). Version 3.23.0 fixes the vulnerability.

Affected Software

2 affected components
FreeRDP freerdp<3.23.0
FreeRDP freerdp<3.23.0

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade FreeRDP to a version that resolves this vulnerability.

    Fixed in 3.23.0

Event History

Feb 25, 2026
CVE Published
via MITRE·08:59 PM
Data Sourced
via MITRE·08:59 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·09:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Feb 26, 2026
Data Sourced
via Red Hat·06:01 AM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2026-26965?

CVE-2026-26965 has been assessed with a high severity level due to potential buffer overflow vulnerabilities.

2

How do I fix CVE-2026-26965?

To remediate CVE-2026-26965, upgrade FreeRDP to version 3.23.0 or later.

3

What types of systems are affected by CVE-2026-26965?

CVE-2026-26965 affects FreeRDP installations prior to version 3.23.0.

4

What impact does CVE-2026-26965 have on affected systems?

CVE-2026-26965 can potentially lead to arbitrary code execution on affected systems.

5

Is there a workaround for CVE-2026-26965?

There are no known workarounds for CVE-2026-26965; updating the software is essential.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203