PatchSiren

neutrinolabs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM neutrinolabs CVE published 2026-07-20

CVE-2026-44978

CVE-2026-44978 is a heap out-of-bounds read vulnerability within the FIPS-specific receive paths of xrdp, an open-source RDP server. The vulnerability exists in versions 0.10.6 and prior. It is not exploitable in the default configuration of xrdp. The vulnerability is only exploitable when the security layer is set to security_layer=negotiate or security_layer=rdp, and the crypto level is changed to crypt [truncated]

HIGH neutrinolabs CVE published 2026-07-20

CVE-2026-44178

CVE-2026-44178 is a high-severity heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism of xrdp, an open-source RDP server. The vulnerability exists in versions 0.10.6 and prior. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity, leading to heap memory corruption. This may result [truncated]

MEDIUM neutrinolabs CVE published 2026-07-20

CVE-2026-42218

CVE-2026-42218 is a timing side-channel vulnerability in xrdp, an open source RDP server. Versions 0.10.6 and prior are affected, allowing remote attackers to infer the existence of a username on the system via username enumeration. This issue has been fixed in version 0.10.6.1. The vulnerability has a CVSS score of 5.3 and a severity of MEDIUM. Users of xrdp versions 0.10.6 and prior should update to ver [truncated]

HIGH neutrinolabs CVE published 2026-07-20

CVE-2026-41521

CVE-2026-41521 is an integer overflow vulnerability in xrdp, an open source RDP server, affecting versions 0.10.6 and prior. The vulnerability occurs in the vnc-any connection mode of xrdp. A remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation. This results in an undersized allocation for the image buffer. When the incoming image data is [truncated]

CRITICAL neutrinolabs CVE published 2026-07-20

CVE-2026-41252

CVE-2026-41252 is a critical vulnerability in xrdp, an open-source RDP server. The issue is caused by a missing bounds check, leading to a heap-based buffer overflow when operating in vnc-any mode. This occurs during the handling of RFB protocol color map messages from a VNC server, where incoming color indices are not properly validated. A malicious VNC server can exploit this flaw by sending crafted mes [truncated]