Bug 2502913 (CVE-2026-55639) - CVE-2026-55639 xrdp: improper input validation in MCS data processing leads to potential information leak
Summary: CVE-2026-55639 xrdp: improper input validation in MCS data processing leads t...
Keywords:
Status: NEW
Alias: CVE-2026-55639
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 2502974 2502975
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-07-20 18:02 UTC by OSIDB Bzimport
Modified: 2026-07-20 19:47 UTC (History)
0 users

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-07-20 18:02:08 UTC
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the parsing of Client Security Data within the Client MCS Connect Initial PDU with GCC Conference Create Request during the connection sequence. During the initial capability and security negotiation phase, the parser fails to perform sufficient length validation for the incoming data block. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed data. Due to missing bounds checks, the xrdp process may read a small number of bytes beyond the declared data block boundary, potentially disclosing process memory contents that could be combined with other vulnerabilities. This issue has been fixed in version 0.10.6.1.


Note You need to log in before you can comment on or make changes to this bug.