PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-55192 FreeRDP CVE debrief

A vulnerability in FreeRDP's H.264 decoder backends can cause memory disclosure or client crashes when connecting to a malicious RDP server. The issue is fixed in version 3.27.0. This vulnerability allows a malicious RDP server to provide an AVC420 or AVC444 bitstream whose decoded frame is smaller than the negotiated surface, causing yuv420_context_decode and the YUV-to-RGB conversion paths to read beyond the decoder-owned planes in libfreerdp/codec/h264.c and the selected H.264 backend.

Vendor
FreeRDP
Product
Unknown
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-19
Original CVE updated
2026-09-22
Advisory published
2026-08-19
Advisory updated
2026-09-22

Who should care

Defenders responsible for systems using FreeRDP, particularly those allowing remote desktop connections, should assess exposure and prioritize updates to prevent potential issues. This includes reviewing the current version of FreeRDP in use, identifying systems that may be vulnerable, and planning updates to version 3.27.0 or later. Additionally, defenders should monitor for unusual client behavior and review compensating controls for exposed systems. IT,

Why it matters

CVE-2026-55192 in FreeRDP's H.264 decoder backends can lead to memory disclosure or client crashes when connecting to malicious RDP servers, requiring defenders to assess exposure and prioritize updates.

  • Memory disclosure of client data
  • Potential client crashes or instability
  • Need for verification of FreeRDP version and exposure
  • Prioritization of updates to version 3.27.0 or later

Technical summary

FreeRDP's H.264 decoder backends do not properly validate decoded frame sizes against RDPGFX surface dimensions, allowing a malicious RDP server to cause memory disclosure or client crashes. This issue arises from the decoder backends returning YUV planes sized from the bitstream without comparing the decoded width and height to the RDPGFX surface dimensions used to validate region rectangles. The vulnerability can be mitigated by ensuring that the decoded frame sizes are properly validated against the negotiated surface dimensions.

Defensive priority

Defenders should prioritize updating FreeRDP to version 3.27.0 or later to prevent potential memory disclosure or client crashes when connecting to untrusted RDP servers.

Recommended defensive actions

  • Update FreeRDP to version 3.27.0 or later
  • Restrict access to trusted RDP servers
  • Monitor for unusual client behavior
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, its impact, and the fixed version. However, there is no information on known exploitation or affected systems beyond the vulnerable FreeRDP versions.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-55192 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-55192

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-55192 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-55192

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.