Bug 2509996 (CVE-2026-67306) - CVE-2026-67306 FreeRDP: FreeRDP: Out-of-bounds read vulnerability via crafted RDP messages
Summary: CVE-2026-67306 FreeRDP: FreeRDP: Out-of-bounds read vulnerability via crafted...
Keywords:
Status: NEW
Alias: CVE-2026-67306
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2510302 2510303
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-08-01 13:02 UTC by OSIDB Bzimport
Modified: 2026-08-03 07:35 UTC (History)
2 users (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-08-01 13:02:23 UTC
FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder functions planar_decompress_plane_rle and planar_decompress_plane_rle_only in libfreerdp/codec/planar.c. Only the 1-byte control byte is bounds-checked; the subsequent 0–15 attacker-declared raw bytes are read without validating that the source buffer contains them. A malicious or compromised RDP server can send a truncated planar-encoded bitmap or surface update (reachable via both the Bitmap Update PDU and RDPGFX Surface Command paths) that causes the client to read past the end of the source buffer. The issue is fixed in FreeRDP 3.29.0.


Note You need to log in before you can comment on or make changes to this bug.