Bug 2499155 (CVE-2026-57158) - CVE-2026-57158 FreeRDP: FreeRDP: Information disclosure via truncated RDPGFX planar payload
Summary: CVE-2026-57158 FreeRDP: FreeRDP: Information disclosure via truncated RDPGFX ...
Keywords:
Status: NEW
Alias: CVE-2026-57158
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2499197 2499198 2499199
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-10 20:01 UTC by OSIDB Bzimport
Modified: 2026-07-10 21:00 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-10 20:01:46 UTC
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing a malicious RDP server to send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the input buffer. This issue is fixed in version 3.28.0.


Note You need to log in before you can comment on or make changes to this bug.