PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-23532 FreeRDP CVE debrief

CVE-2026-23532 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. A client-side heap buffer overflow occurs due to a mismatch between destination rectangle clamping and the actual copy size in the FreeRDP client’s `gdi_SurfaceToSurface` path. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue. Users should update to version 3.21.0 or later to mitigate this vulnerability. Additionally, defenders should monitor for potential exploitation attempts and apply compensating controls as needed.

Vendor
FreeRDP
Product
Unknown
CVSS
HIGH 7.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-19
Original CVE updated
2026-07-15
Advisory published
2026-01-19
Advisory updated
2026-07-15

Who should care

Organizations using FreeRDP clients should prioritize updating to version 3.21.0 or later. Additionally, defenders and security teams should be aware of the potential for exploitation and monitor for suspicious activity. Red Hat users can refer to errata RHSA-2026:2048, RHSA-2026:2081, RHSA-2026:2222, and others for specific guidance.

Technical summary

The vulnerability exists in the FreeRDP client’s `gdi_SurfaceToSurface` path, where a mismatch between destination rectangle clamping and the actual copy size leads to a client-side heap buffer overflow. This can be triggered by a malicious server, potentially causing a crash (DoS) and heap corruption with code-execution risk. The issue is patched in version 3.21.0. The Common Vulnerability Scoring System (CVSS) score for this vulnerability is 7.7, indicating a high severity level.

Defensive priority

High priority should be given to updating FreeRDP clients to version 3.21.0 or later. Defenders should also enhance monitoring for potential exploitation attempts and apply additional security measures as necessary.

Recommended defensive actions

  • Update FreeRDP clients to version 3.21.0 or later.
  • Monitor for potential exploitation attempts.
  • Apply compensating controls as needed.
  • Refer to Red Hat errata for specific guidance (RHSA-2026:2048, RHSA-2026:2081, RHSA-2026:2222, etc.).
  • Review and update incident response plans.

Evidence notes

The CVE-2026-23532 vulnerability is documented in the official CVE record and the National Vulnerability Database (NVD). Additional information and patches are available from the FreeRDP GitHub repository and Red Hat errata pages. The vulnerability has a CVSS score of 7.7, indicating high severity.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-23532 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-23532

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-23532 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-23532

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source reference

    Unverified legacy reference

    URL: https://github.com/FreeRDP/FreeRDP/blob/38514dfa5813aa945a86cfbcec279033f8394468/libfreerdp/gdi/gfx.c

    [email protected] - Product

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/FreeRDP/FreeRDP/releases/tag/3.21.0

    [email protected] - Release Notes

  • Mitigation or vendor reference

    Unverified legacy reference

    URL: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fq8c-87hj-7gvr

    [email protected] - Exploit, Vendor Advisory

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:2048

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:2081

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:2222

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

  • Source reference

    Unverified legacy reference

    URL: https://access.redhat.com/errata/RHSA-2026:2714

    0b0ca135-0b70-47e7-9f44-1890c2a1c46c

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.