xrdp is an open source remote desktop protocol (RDP) server. In versions prior to 0.9.23 improper handling of session establishment errors allows bypassing OS-level session restrictions. The `auth_start_session` function can return non-zero (1) value on, e.g., PAM error which may result in in session restrictions such as max concurrent sessions per user by PAM (ex ./etc/security/limits.conf) to be bypassed. Users (administrators) don't use restrictions by PAM are not affected. This issue has been addressed in release version 0.9.23. Users are advised to upgrade. There are no known workarounds for this issue.
CVSS Details
- CVSS 3.1 Base Score: 2.6
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | alpine-linux-upgrade-xrdp | Aug 22, 2024 | Aug 30, 2023 | |
| Debian | debian-upgrade-xrdp | May 15, 2025 | Aug 30, 2023 | |
| Freebsd | freebsd-upgrade-package-xrdp | Sep 28, 2023 | Sep 27, 2023 | |
| Suse | — | suse-upgrade-libpainter0suse-upgrade-librfxencode0suse-upgrade-xrdpsuse-upgrade-xrdp-devel | Sep 25, 2023 | Aug 30, 2023 |
| Ubuntu | ubuntu-pro-upgrade-xrdp | Nov 13, 2023 | Aug 30, 2023 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub