CVE-2026-85090: FreeRDP before 3.31.0 Heap Out-of-Bounds Read via AVC444
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the generalChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFXAVC444BITMAPSTREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker controlling a malicious RDP server can target a FreeRDP client. Exploitation requires the client user to initiate or interact with an RDP connection to that server.
What FreeRDP configurations are affected?
The issue is triggered while processing AVC444 bitmap data during chroma plane reconstruction. The provided information does not identify any configuration requirement beyond handling a malicious RDP server's crafted RFX_AVC444_BITMAP_STREAM.
How can I determine whether my deployment is vulnerable?
Check the installed FreeRDP version. Versions before 3.31.0 are affected; version 3.31.0 is identified as the release containing the fix.
What should I do if I cannot update immediately?
Avoid connecting affected FreeRDP clients to untrusted or attacker-controlled RDP servers, since the server supplies the crafted bitmap stream that triggers the out-of-bounds read.