CVE-2026-41252: xrdp: lib_palette_update Heap Buffer Overflow & RCE
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during the handling of RFB protocol color map messages from a VNC server, where incoming color indices are not properly validated. A malicious VNC server can exploit this flaw by sending crafted messages with out-of-range values, leading to an out-of-bounds write on the heap. This memory corruption can result in a denial of service (DoS) or potentially allow remote code execution (RCE) prior to authentication. This issue has been fixed in version 0.10.6.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
xrdpto a version that resolves this vulnerability.Fixed in 0.10.6.1Patch xrdp: lib_palette_update Heap Buffer Overflow & RCE
Event History
Frequently Asked Questions
What is the severity of CVE-2026-41252?
CVE-2026-41252 has a critical severity rating of 9.8.
How do I fix CVE-2026-41252?
To fix CVE-2026-41252, upgrade to xrdp version 0.10.6.1 or later.
What vulnerability does CVE-2026-41252 describe?
CVE-2026-41252 describes a heap buffer overflow vulnerability in xrdp when handling RFB protocol color map messages.
What types of attacks can CVE-2026-41252 facilitate?
CVE-2026-41252 can facilitate remote code execution due to its heap-based buffer overflow.
Which versions of xrdp are affected by CVE-2026-41252?
xrdp versions 0.10.6 and prior are affected by CVE-2026-41252.