PatchSiren cyber security CVE debrief
CVE-2026-55192 FreeRDP CVE debrief
A vulnerability in FreeRDP's H.264 decoder backends can cause memory disclosure or client crashes when connecting to a malicious RDP server. The issue is fixed in version 3.27.0. This vulnerability allows a malicious RDP server to provide an AVC420 or AVC444 bitstream whose decoded frame is smaller than the negotiated surface, causing yuv420_context_decode and the YUV-to-RGB conversion paths to read beyond the decoder-owned planes in libfreerdp/codec/h264.c and the selected H.264 backend.
- Vendor
- FreeRDP
- Product
- Unknown
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-19
- Original CVE updated
- 2026-09-22
- Advisory published
- 2026-08-19
- Advisory updated
- 2026-09-22
Who should care
Defenders responsible for systems using FreeRDP, particularly those allowing remote desktop connections, should assess exposure and prioritize updates to prevent potential issues. This includes reviewing the current version of FreeRDP in use, identifying systems that may be vulnerable, and planning updates to version 3.27.0 or later. Additionally, defenders should monitor for unusual client behavior and review compensating controls for exposed systems. IT,
Why it matters
CVE-2026-55192 in FreeRDP's H.264 decoder backends can lead to memory disclosure or client crashes when connecting to malicious RDP servers, requiring defenders to assess exposure and prioritize updates.
- Memory disclosure of client data
- Potential client crashes or instability
- Need for verification of FreeRDP version and exposure
- Prioritization of updates to version 3.27.0 or later
Technical summary
FreeRDP's H.264 decoder backends do not properly validate decoded frame sizes against RDPGFX surface dimensions, allowing a malicious RDP server to cause memory disclosure or client crashes. This issue arises from the decoder backends returning YUV planes sized from the bitstream without comparing the decoded width and height to the RDPGFX surface dimensions used to validate region rectangles. The vulnerability can be mitigated by ensuring that the decoded frame sizes are properly validated against the negotiated surface dimensions.
Defensive priority
Defenders should prioritize updating FreeRDP to version 3.27.0 or later to prevent potential memory disclosure or client crashes when connecting to untrusted RDP servers.
Recommended defensive actions
- Update FreeRDP to version 3.27.0 or later
- Restrict access to trusted RDP servers
- Monitor for unusual client behavior
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. However, there is no information on known exploitation or affected systems beyond the vulnerable FreeRDP versions.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-55192 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-55192
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-55192 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55192
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/FreeRDP/FreeRDP/commit/0cd45b70bb1fe6befd258ff64c46461947e99adb
[email protected] - Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/FreeRDP/FreeRDP/pull/12873
[email protected] - Issue Tracking, Patch
-
Source reference
Unverified legacy reference
URL: https://github.com/FreeRDP/FreeRDP/releases/tag/3.27.0
[email protected] - Release Notes
-
Source reference
Unverified legacy reference
URL: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3mmf-qh4f-frm6
[email protected] - Exploit, Mitigation, Vendor Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.