Bug 2483470 (CVE-2026-45700)

Summary: CVE-2026-45700 freerdp: FreeRDP: Out-of-bounds write in planar bitmap decoder allows arbitrary code execution
Product: [Other] Security Response Reporter: OSIDB Bzimport <bzimport>
Component: vulnerabilityAssignee: Product Security DevOps Team <prodsec-dev>
Status: NEW --- QA Contact:
Severity: high Docs Contact:
Priority: high    
Version: unspecifiedCC: rhel-process-autobot, watson-tool-maintainers
Target Milestone: ---Keywords: Security
Target Release: ---   
Hardware: All   
OS: Linux   
Whiteboard:
Fixed In Version: Doc Type: ---
Doc Text:
A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. The planar bitmap decoder contains an out-of-bounds heap write vulnerability when processing RLE planar data. A remote attacker could exploit this by providing specially crafted RLE planar data, leading to an out-of-bounds write. This could result in arbitrary code execution or a denial of service.
Story Points: ---
Clone Of: Environment:
Last Closed: Type: ---
Regression: --- Mount Type: ---
Documentation: --- CRM:
Verified Versions: Category: ---
oVirt Team: --- RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: --- Target Upstream Version:
Embargoed:
Bug Depends On: 2491683, 2491684, 2491685    
Bug Blocks:    

Description OSIDB Bzimport 2026-05-29 21:01:43 UTC
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against the caller-provided destination stride (nDstStep) even when it is writing into the internal temp buffer pTempData. An attacker can bypass the check with a large nDstStep and a large nXDst, causing planar_decompress_plane_rle() to write past the end of pTempData. This vulnerability is fixed in 3.26.0.

Comment 3 errata-xmlrpc 2026-07-07 13:53:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10

Via RHSA-2026:36203 https://access.redhat.com/errata/RHSA-2026:36203

Comment 4 errata-xmlrpc 2026-07-09 09:34:20 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9

Via RHSA-2026:37207 https://access.redhat.com/errata/RHSA-2026:37207

Comment 5 errata-xmlrpc 2026-07-13 07:23:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8

Via RHSA-2026:38501 https://access.redhat.com/errata/RHSA-2026:38501

Comment 6 errata-xmlrpc 2026-07-27 02:27:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.4 Update Services for SAP Solutions

Via RHSA-2026:46383 https://access.redhat.com/errata/RHSA-2026:46383

Comment 7 errata-xmlrpc 2026-07-27 02:42:13 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 10.0 Extended Update Support

Via RHSA-2026:46393 https://access.redhat.com/errata/RHSA-2026:46393

Comment 8 errata-xmlrpc 2026-07-27 03:17:19 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On

Via RHSA-2026:46384 https://access.redhat.com/errata/RHSA-2026:46384

Comment 9 errata-xmlrpc 2026-07-27 03:28:48 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.8 Update Services for SAP Solutions
  Red Hat Enterprise Linux 8.8 Telecommunications Update Service

Via RHSA-2026:46388 https://access.redhat.com/errata/RHSA-2026:46388

Comment 10 errata-xmlrpc 2026-07-27 03:29:04 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support
  Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On

Via RHSA-2026:46389 https://access.redhat.com/errata/RHSA-2026:46389

Comment 11 errata-xmlrpc 2026-07-28 11:24:26 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.2 Update Services for SAP Solutions

Via RHSA-2026:47048 https://access.redhat.com/errata/RHSA-2026:47048

Comment 12 errata-xmlrpc 2026-07-28 11:46:12 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 9.6 Extended Update Support

Via RHSA-2026:47049 https://access.redhat.com/errata/RHSA-2026:47049

Comment 13 errata-xmlrpc 2026-07-28 21:00:34 UTC
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7 Extended Lifecycle Support

Via RHSA-2026:47201 https://access.redhat.com/errata/RHSA-2026:47201