These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
The CVE-2026-55648 vulnerability affects FreeRDP, a free implementation of the Remote Desktop Protocol, prior to version 3.27.0. This vulnerability involves an integer wrap in the calculation of image data size, allowing a malicious RDP server to potentially execute arbitrary code on affected clients. Organizations should review and update their installations to prevent potential exploitation. The CVE rec [truncated]
FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.
A heap-based buffer overflow vulnerability exists in FreeRDP before version 3.30.0 (and 3.29.0 or earlier) in the Windows clipboard client's CliprdrStream_Read function. This function is located in the client/Windows/wf_cliprdr.c file. The vulnerability occurs when an OLE paste consumer, such as explorer.exe, calls IStream::Read with a fixed-size buffer. The CliprdrStream_Read function requests file conte [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:17:00.250Z and has not been modified since then. CVE-2026-67306 is an out-of-bounds read vulnerability in FreeRDP versions 3.28.0 and earlier. The issue is fixed in FreeRDP 3.29.0. Evidence is limited; further verification is recommended. Organizations should verify their deployments, review o [truncated]
The FreeRDP Windows client before version 3.29.0 contains a heap buffer overflow vulnerability in the clipboard virtual channel. This vulnerability occurs when processing CLIPRDR_FILE_CONTENTS_RESPONSE PDUs without validating the server-provided size against the destination buffer. A malicious RDP server can exploit this by sending a response with a data payload significantly larger than requested, leadin [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:16:59.970Z and has not been modified since then. FreeRDP before 3.29.0 contains a null pointer dereference vulnerability in smartcard device control request cleanup when reader-state decoding fails. Attackers can send malformed smartcard IRP requests with non-zero cReaders and truncated reader [truncated]
FreeRDP versions prior to 3.29.0 are affected by a divide-by-zero vulnerability in the rdpecam camera redirection client. The vulnerability occurs when a malicious or compromised RDP server sends a StartStreamsRequest with FrameRateDenominator set to zero, causing an integer division by zero and termination of the FreeRDP client process. Users of FreeRDP versions prior to 3.29.0, especially those with cam [truncated]
FreeRDP before 3.29.0 contains out-of-bounds read vulnerabilities in the async update message proxy for the PolygonSC and PolygonCB primary drawing orders. The vulnerabilities occur when AsyncUpdate is enabled, causing update_message_PolygonSC() and update_message_PolygonCB() to allocate a fresh points array but copy point data from the address of the order structure instead of from polygonSC->points / po [truncated]
FreeRDP before 3.29.0 contains client-side heap use-after-free vulnerabilities in the async update message proxy for RAIL WINDOW_STATE_ORDER and NOTIFY_ICON_STATE_ORDER when AsyncUpdate is enabled. A malicious or compromised RDP server can exploit these vulnerabilities by sending crafted update orders, potentially causing memory corruption or a client crash. The CVE record was published on 2026-08-01T13:1 [truncated]
CVE-2026-67299 is a client-side heap use-after-free vulnerability in FreeRDP before version 3.29.0. The vulnerability occurs in the async update message proxy for WINDOW_ICON_ORDER when AsyncUpdate is enabled. A malicious RDP server can trigger the use-after-free by sending a crafted RAIL Window Alternate Secondary Order with WINDOW_ORDER_ICON, leading to memory corruption and client crashes. FreeRDP user [truncated]
FreeRDP versions 3.28.0 and earlier contain a heap buffer overflow in the server-side RAIL channel handler. This vulnerability is triggered when processing a RAIL PDU header, where the code subtracts RAIL_PDU_HEADER_LENGTH from the peer-controlled orderLength field without first verifying orderLength is at least the header length. Consequently, for orderLength values 0..3, an unsigned integer underflow oc [truncated]
FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT when processing Transfer-Encoding: chunked HTTP responses in http_response_recv_body(). Attackers controlling a malicious RD Gateway endpoint can send oversized chunked response bodies to exhaust client memory resources without triggering the configured size limit. This vulnerability affects FreeRDP, a remote desktop protocol implementation, a [truncated]
FreeRDP before version 3.29.0 contains a denial of service vulnerability in the RDPEI server channel handler. The vulnerability occurs when the RDPEI server channel handler fails to validate the maximum PDU body length before stream allocation, allowing a malicious RDP client to send a header-only RDPEI message with a large declared body length, causing excessive memory allocation on the server. This issu [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:16:58.670Z and has not been modified since then. FreeRDP before 3.29.0 fails to properly validate server-supplied RDPDR paths in drive redirection, allowing attackers to access prefix-sibling paths outside the configured shared root. This vulnerability can be exploited by a malicious RDP serve [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:16:58.380Z and has not been modified since then. CVE-2026-67293 is an improper certificate hostname validation vulnerability in FreeRDP before 3.29.0. The TLS hostname matcher incorrectly accepts wildcard certificates for multi-label subdomains, potentially weakening TLS server authentication [truncated]
The CVE-2026-67292 vulnerability is a buffer over-disclosure issue in the gateway WebSocket transport of FreeRDP before version 3.29.0. This vulnerability allows a malicious gateway/WebSocket peer to cause the client to reply with an overlong Pong that discloses bytes beyond the received payload. A zero-length Ping causes an assertion and terminates the client, resulting in a denial of service. Organizati [truncated]
CVE-2026-67291 is a heap out-of-bounds read vulnerability in FreeRDP before version 3.29.0. The issue occurs in update_process_glyph_fragments()/glyph_cache_fragment_put() in libfreerdp/cache/glyph.c. A malicious RDP server can send a short fragment with an oversized declared size, causing the client to read beyond the allocated buffer, resulting in a client crash. This vulnerability has a CVSS score of 8 [truncated]
CVE-2026-67290 is a critical vulnerability in FreeRDP's TSMF FFmpeg decoder, allowing for a heap out-of-bounds read when parsing AVC1 MPEG2VIDEOINFO media types with insufficient ExtraData. This vulnerability has a high CVSS score of 8.7, indicating a high-priority risk. Organizations using FreeRDP versions before 3.29.0 should prioritize patching. Affected operators, platforms, and security teams should [truncated]
FreeRDP before version 3.29.0 is vulnerable to a critical issue (CVSS Score: 9.3) that allows a malicious RDP server to inject arbitrary headers or requests into the HTTP proxy CONNECT request. This occurs because FreeRDP does not validate CRLF and control characters in the server-controlled RDP redirection TargetNetAddress field. Organizations using FreeRDP for remote desktop connections should be aware [truncated]
The CVE-2026-67288 vulnerability exists in FreeRDP before version 3.29.0, which contains a null pointer dereference in smartcard cache request decoders. This vulnerability allows attackers to cause client process termination via crafted smartcard cache requests when smartcard emulation is enabled. Users of affected FreeRDP deployments should prioritize patching or upgrading to version 3.29.0 or later. The [truncated]
FreeRDP before 3.29.0 contains multiple TLS certificate identity validation weaknesses. This CVE record was published on 2026-08-01T13:16:57.487Z and has not been modified since then. The vulnerability affects users of FreeRDP versions before 3.29.0, administrators of systems using FreeRDP, and security teams monitoring for TLS certificate validation bypass vulnerabilities. The weaknesses are located in t [truncated]
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-01T13:16:57.320Z and has not been modified since then. FreeRDP before 3.29.0 contains an out-of-bounds heap read vulnerability in the UVC H.264 extension-unit parser that fails to validate descriptor length before accessing the GUID field. A local attacker with a malicious USB video camera can trigg [truncated]
CVE-2026-64624 is a high-severity vulnerability in FreeRDP before 3.28.0. The vulnerability occurs because FreeRDP treats lines beginning with a forward slash in RDP files as raw command-line options, exposing the entire CLI parser surface to untrusted files. Attackers can craft malicious RDP files with /rdp2tcp, /cert:ignore, or /drive options to execute arbitrary commands, bypass certificate validation, [truncated]
CVE-2026-64621 is a critical double-free vulnerability in FreeRDP before version 3.28.0. The vulnerability exists in the freerdp_client_rdp_file_apply_to_settings() function when parsing the selectedmonitors field of a .rdp connection file. An attacker can exploit this vulnerability by convincing a victim to open a crafted .rdp file with oversized monitor tokens, potentially leading to a size-controlled d [truncated]
A heap-based buffer overflow vulnerability exists in FreeRDP before version 3.28.0 in the crypto_rsa_common() function. The function writes the modular-exponentiation result into the caller's output buffer via BN_bn2bin() and only afterward checks output_length > out_length, so out-of-bounds bytes are written before the bounds check. This vulnerability could allow an unauthenticated attacker to cause a de [truncated]
CVE-2026-57158 is a MEDIUM severity vulnerability in FreeRDP clients using the GFX pipeline, with an incomplete fix for CVE-2026-23530. A malicious RDP server can send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the input buffer. This issue is fixed in version 3.28.0. The vulnerability exists in the planar_decompress_plane_rle_only function in libfreerdp/codec/planar.c [truncated]
FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled are vulnerable to a heap read issue. This issue allows a malicious RDP client to trigger a 1- to 2-byte out-of-bounds heap read. The vulnerability is fixed in version 3.28.0. Users of FreeRDP server implementations with the MS-RDPECAM camera device enumerator channel enabled should review and apply the provided pat [truncated]
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count by sizeof(DELTA_POINT), allowing a malicious RDP peer to allocate an undersized heap buffer and then write beyond it during initialization. This issue is fix [truncated]
CVE-2026-55827 is a heap out-of-bounds write vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. This issue allows a malicious RDP server to trigger a heap out-of-bounds write with attacker-controlled offset and content when FreeRDP clients are launched with the non-default /cache:codec:rfx option. Affected product deployments should be identified, and owners assigned for follo [truncated]
CVE-2026-56297 is a high-severity use-after-free vulnerability in FreeRDP before 3.22.0. A malicious RDP server can trigger a race condition by sending DYNVC_DATA and DYNVC_CLOSE messages concurrently, causing heap-use-after-free in the drdynvc client thread and potentially enabling remote code execution or denial of service. The vulnerability exists in dvcman_channel_close and dvcman_call_on_receive due [truncated]
FreeRDP versions prior to 3.26.0 contain an out-of-bounds heap write vulnerability in the planar bitmap decoder. The flaw exists in `freerdp_bitmap_decompress_planar()` within `libfreerdp/codec/planar.c`, where the function validates the X destination coordinate `nXDst` against the caller-provided destination stride (`nDstStep`) even when writing to an internal temporary buffer (`pTempData`). An attacker [truncated]
## Summary FreeRDP versions prior to 3.26.0 contain a heap use-after-free/double-free vulnerability in the RDPEAR NDR parser. A malicious RDP server can trigger memory corruption by reusing the same non-null NDR pointer reference ID across multiple logical pointer fields, causing the parser to assign the same heap object to multiple output fields. The generic destructor then independently frees both point [truncated]
A heap-buffer-overflow vulnerability exists in FreeRDP client versions prior to 3.26.0. The flaw resides in the `gdi_CacheToSurface` function, where a destination rectangle is validated after being clamped to UINT16_MAX, but the subsequent copy operation uses the original `cacheEntry->width/height` values. This mismatch allows a malicious RDP server to trigger an out-of-bounds heap write when the client h [truncated]
A heap-buffer-overflow vulnerability exists in FreeRDP's server-side clipboard (cliprdr) channel prior to version 3.26.0. A malicious RDP client can trigger this flaw by sending a CB_CLIP_CAPS PDU with a malformed capabilitySetLength value that is too small. This memory corruption can crash the server process, resulting in remote denial of service, and may be exploitable for code execution. The vulnerabil [truncated]
A heap-buffer-overflow vulnerability exists in FreeRDP versions prior to 3.26.0 within the gdi_CacheToSurface function. The flaw stems from a validation logic error: rectangle coordinates are clamped to UINT16_MAX during bounds checking, but subsequent copy operations use unclamped cache entry dimensions. This discrepancy allows a malicious RDP server to trigger out-of-bounds heap writes, potentially lead [truncated]
CVE-2026-33984 is a heap buffer overflow vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability exists in the resize_vbar_entry() function in libfreerdp/codec/clear.c. Prior to version 3.24.2, an attacker can exploit this vulnerability by providing malicious pixel data, leading to a heap buffer overflow. This issue has been patched in version 3.24.2. Users should [truncated]
CVE-2026-31806 is a critical heap buffer overflow vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability exists in the gdi_surface_bits() function, which processes SURFACE_BITS_COMMAND messages sent by the RDP server. A malicious RDP server can supply crafted bmp.width and bmp.height values that exceed the expected surface size, leading to a heap buffer overflow. [truncated]
CVE-2026-26965 is a heap out-of-bounds write vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability allows a remote, unauthenticated attacker to perform a heap out-of-bounds write with attacker-controlled offset and pixel data on any connecting FreeRDP client. This can lead to control-flow–relevant corruption, including the overwriting of a function pointer. The [truncated]
CVE-2026-26955 is a heap buffer overflow vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. A malicious RDP server can trigger the vulnerability by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. This allows attacker-controlled data to reach image copy routines that write into surface data without bounds enforcement. The vulnerability [truncated]
CVE-2026-24678 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability, fixed in version 3.22.0, is a use-after-free issue in the ecam_channel_write function. This occurs when a capture thread sends sample responses using a freed channel callback after a device channel close. The vulnerability has a CVSS score of 8.7 and is considered HIGH sever [truncated]
CVE-2026-23884 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability, caused by offscreen bitmap deletion leaving `gdi->drawing` pointing to freed memory, can lead to a use-after-free (UAF) condition when related update packets arrive. This can cause a crash (DoS) and potentially lead to heap corruption with code-execution risk, depending on a [truncated]
CVE-2026-23534 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. A client-side heap buffer overflow occurs when crafted band coordinates allow writes past the end of the destination surface buffer. A malicious server can trigger a client-side heap buffer overflow, causing a crash (DoS) and potential heap corruption with code-execution risk depending on allo [truncated]
CVE-2026-23532 is a high-severity vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. A client-side heap buffer overflow occurs due to a mismatch between destination rectangle clamping and the actual copy size in the FreeRDP client’s `gdi_SurfaceToSurface` path. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap corruptio [truncated]
CVE-2026-23531 is a high-severity vulnerability in FreeRDP's ClearCodec. Prior to version 3.21.0, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle. This allows an out-of-bounds read/write via crafted RDPGFX surface updates. A malicious server can trigger a client-side heap buffer overflow, causing a crash (DoS) and potential [truncated]
CVE-2026-22859 is a medium-severity vulnerability in the FreeRDP URBDRC client. The vulnerability arises from a lack of proper bounds checking on server-supplied MSUSB_INTERFACE_DESCRIPTOR values, which are then used as indices in libusb_udev_complete_msconfig_setup. This can lead to an out-of-bounds read. The vulnerability has been fixed in FreeRDP version 3.20.1. Users of FreeRDP should update to this v [truncated]
CVE-2026-22858 is a global-buffer-overflow vulnerability in FreeRDP's Base64 decoding path. The issue arises from implementation-defined char signedness, particularly on Arm/AArch64 builds where plain char is treated as unsigned. This leads to a potential out-of-bounds access when non-ASCII bytes are used as an index into a global lookup table. The vulnerability is fixed in FreeRDP version 3.20.1. Users s [truncated]
CVE-2026-22853 is a heap buffer overflow vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability exists in RDPEAR's NDR array reader, which does not perform bounds checking on the on-wire element count. This can cause the reader to write past the heap buffer allocated from hints, leading to a heap buffer overflow. The vulnerability is fixed in version 3.20.1. User [truncated]