PatchSiren cyber security CVE debrief
CVE-2026-23532 FreeRDP CVE debrief
CVE-2026-23532 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. A client-side heap buffer overflow occurs due to a mismatch between destination rectangle clamping and the actual copy size in the FreeRDP client’s `gdi_SurfaceToSurface` path. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue. Users should update to version 3.21.0 or later to mitigate this vulnerability. Additionally, defenders should monitor for potential exploitation attempts and apply compensating controls as needed.
- Vendor
- FreeRDP
- Product
- Unknown
- CVSS
- HIGH 7.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-01-19
- Original CVE updated
- 2026-07-15
- Advisory published
- 2026-01-19
- Advisory updated
- 2026-07-15
Who should care
Organizations using FreeRDP clients should prioritize updating to version 3.21.0 or later. Additionally, defenders and security teams should be aware of the potential for exploitation and monitor for suspicious activity. Red Hat users can refer to errata RHSA-2026:2048, RHSA-2026:2081, RHSA-2026:2222, and others for specific guidance.
Technical summary
The vulnerability exists in the FreeRDP client’s `gdi_SurfaceToSurface` path, where a mismatch between destination rectangle clamping and the actual copy size leads to a client-side heap buffer overflow. This can be triggered by a malicious server, potentially causing a crash (DoS) and heap corruption with code-execution risk. The issue is patched in version 3.21.0. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.7, indicating a high severity level.
Defensive priority
High priority should be given to updating FreeRDP clients to version 3.21.0 or later. Defenders should also enhance monitoring for potential exploitation attempts and apply additional security measures as necessary.
Recommended defensive actions
- Update FreeRDP clients to version 3.21.0 or later.
- Monitor for potential exploitation attempts.
- Apply compensating controls as needed.
- Refer to Red Hat errata for specific guidance (RHSA-2026:2048, RHSA-2026:2081, RHSA-2026:2222, etc.).
- Review and update incident response plans.
Evidence notes
The CVE-2026-23532 vulnerability is documented in the official CVE record and the National Vulnerability Database (NVD). Additional information and patches are available from the FreeRDP GitHub repository and Red Hat errata pages. The vulnerability has a CVSS score of 7.7, indicating high severity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-23532 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-23532
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-23532 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23532
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/FreeRDP/FreeRDP/blob/38514dfa5813aa945a86cfbcec279033f8394468/libfreerdp/gdi/gfx.c
[email protected] - Product
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/FreeRDP/FreeRDP/releases/tag/3.21.0
[email protected] - Release Notes
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fq8c-87hj-7gvr
[email protected] - Exploit, Vendor Advisory
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:2048
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:2081
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:2222
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
-
Source reference
Unverified legacy reference
URL: https://access.redhat.com/errata/RHSA-2026:2714
0b0ca135-0b70-47e7-9f44-1890c2a1c46c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.