FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory by sending a crafted WIRE_TO_SURFACE_2 PDU with a `bitmapDataLength` value larger than the actual data in the packet. This can lead to information disclosure or client crashes when a user connects to a malicious server. Versions 2.11.8 and 3.23.0 fix the issue.
CVSS Details
- CVSS 3.1 Base Score: 4.3
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade freerdp | Mar 2, 2026 | Feb 25, 2026 |
| Amazon Linux Ami 2 | — | Upgrade freerdp-libsUpgrade freerdp-develUpgrade libwinpr-develUpgrade freerdp-debuginfoUpgrade freerdpUpgrade libwinpr | May 20, 2026 | May 20, 2026 |
| Amazon_linux_2023 | — | Upgrade freerdp-develUpgrade freerdpUpgrade libwinprUpgrade freerdp-server-debuginfoUpgrade libwinpr-develUpgrade freerdp-debugsourceUpgrade libwinpr-debuginfoUpgrade freerdp-libs-debuginfoUpgrade freerdp-debuginfoUpgrade freerdp-libsUpgrade freerdp-server | Apr 7, 2026 | Feb 25, 2026 |
| Debian | — | Upgrade freerdp3 | Jul 23, 2026 | Jul 23, 2026 |
| Redhat_linux | — | No solution exists | Jul 17, 2026 | Feb 25, 2026 |
| Ubuntu | — | Upgrade libfreerdp3-3 | Mar 19, 2026 | Feb 25, 2026 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub