PatchSiren

FreeRDP CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH FreeRDP CVE published 2026-01-19

CVE-2026-23531

CVE-2026-23531 is a high-severity vulnerability in FreeRDP's ClearCodec. Prior to version 3.21.0, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle. This allows an out-of-bounds read/write via crafted RDPGFX surface updates. A malicious server can trigger a client-side heap buffer overflow, causing a crash (DoS) and potential [truncated]

MEDIUM FreeRDP CVE published 2026-01-14

CVE-2026-22859

CVE-2026-22859 is a medium-severity vulnerability in the FreeRDP URBDRC client. The vulnerability arises from a lack of proper bounds checking on server-supplied MSUSB_INTERFACE_DESCRIPTOR values, which are then used as indices in libusb_udev_complete_msconfig_setup. This can lead to an out-of-bounds read. The vulnerability has been fixed in FreeRDP version 3.20.1. Users of FreeRDP should update to this v [truncated]

MEDIUM FreeRDP CVE published 2026-01-14

CVE-2026-22858

CVE-2026-22858 is a global-buffer-overflow vulnerability in FreeRDP's Base64 decoding path. The issue arises from implementation-defined char signedness, particularly on Arm/AArch64 builds where plain char is treated as unsigned. This leads to a potential out-of-bounds access when non-ASCII bytes are used as an index into a global lookup table. The vulnerability is fixed in FreeRDP version 3.20.1. Users s [truncated]

MEDIUM FreeRDP CVE published 2026-01-14

CVE-2026-22853

CVE-2026-22853 is a heap buffer overflow vulnerability in FreeRDP, a free implementation of the Remote Desktop Protocol. The vulnerability exists in RDPEAR's NDR array reader, which does not perform bounds checking on the on-wire element count. This can cause the reader to write past the heap buffer allocated from hints, leading to a heap buffer overflow. The vulnerability is fixed in version 3.20.1. User [truncated]