Bug 2433417 (CVE-2025-68670)

Summary: CVE-2025-68670 xrdp: xrdp: Remote code execution via unauthenticated stack-based buffer overflow
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: urgent Docs Contact:
Priority: urgent    
Version: unspecifiedCC: fedora
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in xrdp. This unauthenticated stack-based buffer overflow vulnerability allows remote attackers to execute arbitrary code on the target system. The issue arises from improper bounds checking when processing user domain information during the connection sequence, which can lead to overwriting the stack buffer and redirecting execution flow. This could enable an attacker to gain full control over the affected system.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2433438, 2433439, 2433440, 2433441, 2433442    
Bug Blocks:    

Description OSIDB Bzimport 2026-01-27 16:04:50 UTC
xrdp is an open source RDP server. xrdp before v0.10.5 contains an unauthenticated stack-based buffer overflow vulnerability. The issue stems from improper bounds checking when processing user domain information during the connection sequence. If exploited, the vulnerability could allow remote attackers to execute arbitrary code on the target system. The vulnerability allows an attacker to overwrite the stack buffer and the return address, which could theoretically be used to redirect the execution flow. The impact of this vulnerability is lessened if a compiler flag has been used to build the xrdp executable with stack canary protection. If this is the case, a second vulnerability would need to be used to leak the stack canary value. Upgrade to version 0.10.5 to receive a patch. Additionally, do not rely on stack canary protection on production systems.

Comment 2 Zephyr Lykos 2026-06-14 09:53:23 UTC
Should be fixed in 500f161a308d1535ef3d58dc6b6a34646392f048