CVE-2026-44178: xrdp: Channel Data Forwarding Fixed-Size Buffer Overflow
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp process utilizes a fixed-size buffer without adequate bounds checking on the incoming payload. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity, leading to heap memory corruption. This may result in a denial of service or the execution of arbitrary code with the privileges of the xrdp process. This issue has been fixed in version 0.10.6.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
xrdpto a version that resolves this vulnerability.Fixed in 0.10.6.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44178?
The severity of CVE-2026-44178 is rated high with a score of 8.8.
How do I fix CVE-2026-44178?
To fix CVE-2026-44178, upgrade xrdp to version 0.10.6.1 or later.
What type of vulnerability is CVE-2026-44178?
CVE-2026-44178 is a heap-based buffer overflow vulnerability.
What software is affected by CVE-2026-44178?
The vulnerability affects xrdp versions prior to 0.10.6.1.
What can be compromised due to CVE-2026-44178?
Due to CVE-2026-44178, confidentiality, integrity, and availability of affected systems can be compromised.