Bug 2459305 (CVE-2026-32624) - CVE-2026-32624 xrdp: xrdp: Denial of Service via crafted username and domain name
Summary: CVE-2026-32624 xrdp: xrdp: Denial of Service via crafted username and domain ...
Keywords:
Status: NEW
Alias: CVE-2026-32624
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Product Security DevOps Team
QA Contact:
URL:
Whiteboard:
Depends On: 2459625 2459626
Blocks:
TreeView+ depends on / blocked
 
Reported: 2026-04-17 21:01 UTC by OSIDB Bzimport
Modified: 2026-06-14 09:56 UTC (History)
1 user (show)

Fixed In Version:
Clone Of:
Environment:
Last Closed:
Embargoed:


Attachments (Terms of Use)

Description OSIDB Bzimport 2026-04-17 21:01:22 UTC
xrdp is an open source RDP server. Versions through 0.10.5 contain a heap-based buffer overflow vulnerability in its logon processing. In environments where domain_user_separator is configured in xrdp.ini, an unauthenticated remote attacker can send a crafted, excessively long username and domain name to overflow the internal buffer. This can corrupt adjacent memory regions, potentially leading to a Denial of Service (DoS) or unexpected behavior. The domain_name_separator directive is commented out by default, systems are not affected by this vulnerability unless it is intentionally configured. This issue has been fixed in version 0.10.6.

Comment 3 Zephyr Lykos 2026-06-14 09:56:25 UTC
should be fixed in 13a9c73444715deb923c2d16705971f60823db28


Note You need to log in before you can comment on or make changes to this bug.