Bug 2459312 (CVE-2026-35512) - CVE-2026-35512 xrdp: xrdp: Remote Code Execution via heap-based buffer overflow
Summary: CVE-2026-35512 xrdp: xrdp: Remote Code Execution via heap-based buffer overflow
Keywords:
Status: NEW
Alias: CVE-2026-35512
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
high
high
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2459619 2459620
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-17 21:01 UTC by OSIDB Bzimport
Modified: 2026-06-14 09:54 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-17 21:01:46 UTC
xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediately update, they should run xrdp as a non-privileged user (default since 0.10.2) to limit the impact of successful exploitation.

Comment 3 Zephyr Lykos 2026-06-14 09:54:53 UTC
should be fixed in 13a9c73444715deb923c2d16705971f60823db28


Note You need to log in before you can comment on or make changes to this bug.