Logo
vulnerabilityCVE-2026-25941
Name
CVE-2026-25941
Source
NVD ( link)Debian ( link)
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory by sending a crafted WIRE_TO_SURFACE_2 PDU with a `bitmapDataLength` value larger than the actual data in the packet. This can lead to information disclosure or client crashes when a user connects to a malicious server. Versions 2.11.8 and 3.23.0 fix the issue.
Published Date
Updated Date
Workaround
-

Analysis#


Affected Component
Analysis
freerdp
Patched
freerdp3
Patched

Vulnerability Ratings#


4.3
CVSSv31
8.1
CVSSv31
NaN
other

Others affected components#


Name
Project
Project Version
Version
Status
buildroot
2025.02.x
2.11.8
Not Affected
buildroot
master
2.11.8
Not Affected
yocto
kirkstone
2.6.1
Exploitable
yocto
master
2.11.8
Not Affected
yocto
master
3.26.0
Not Affected

Resolved with patches#


freerdp3 (yocto:scarthgap)

#
Title
Author
Resolve
1
[channels,rdpgfx] check available stream length
Armin Novak <armin.novak@thincast.com>
CVE-2026-25941