CVE-2026-57158: FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-23530
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planardecompressplanerleonly in libfreerdp/codec/planar.c, allowing a malicious RDP server to send a truncated RDPGFXCMDIDWIRETOSURFACE1 planar payload that reads one byte past the input buffer. This issue is fixed in version 3.28.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
FreeRDPto a version that resolves this vulnerability.Fixed in 3.28.0Patch CVE-2026-23530
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57158?
The severity of CVE-2026-57158 is rated as medium with a score of 5.1.
What does CVE-2026-57158 affect?
CVE-2026-57158 affects FreeRDP versions from 3.21.0 before 3.28.0, specifically the clients using the GFX pipeline.
What type of vulnerability is identified in CVE-2026-57158?
CVE-2026-57158 is a heap out of bounds read vulnerability due to an incomplete fix for CVE-2026-23530.
How can CVE-2026-57158 be mitigated?
To mitigate CVE-2026-57158, users should update FreeRDP to the latest version that addresses the incomplete fix.
Who can exploit CVE-2026-57158?
A malicious RDP server can exploit CVE-2026-57158 by sending a truncated RDPGFX to vulnerable FreeRDP clients.