CVE-2026-22853
published 2026-01-14CVE-2026-22853: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire…
PriorityP355critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.66%
47.5th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp3 3.20.2+dfsg-1 (forky) | freerdp3 3.20.2+dfsg-1 (forky) |
| debian | freerdp3 | < freerdp3 3.20.2+dfsg-1 (forky) | freerdp3 3.20.2+dfsg-1 (forky) |
| freerdp | freerdp | < 3.20.1 | 3.20.1 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.06.8MEDIUMCVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.8MEDIUM
vendor_debian6.8MEDIUM
vendor_redhat6.8MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2026-03-18
CVE-2026-25954 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled certain RDP packets. A
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
freerdp: FreeRDP heap-buffer-overflow
vendor_redhat·2026-01-14·CVSS 6.8
CVE-2026-22853 [MEDIUM] CWE-787 freerdp: FreeRDP heap-buffer-overflow
freerdp: FreeRDP heap-buffer-overflow
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.
A heap based buffer overflow flaw has been discovered in FreeRDP. In affected versions RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array.
Statement: Red Hat products in their default configuration employ Address Space Layout Randomization (ASLR) which drastically increases the complexity
Debian
CVE-2026-22853: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1...
vendor_debian·2026·CVSS 6.8
CVE-2026-22853 [MEDIUM] CVE-2026-22853: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.
Scope: local
bookworm: open
bullseye: open
VulDB
FreeRDP up to 3.20.0 ndr_read_uint8Array out-of-bounds write (GHSA-47v9-p4gp-w5ch / EUVD-2026-2674)
vuldb·2026-06-11·CVSS 9.8
CVE-2026-22853 [CRITICAL] FreeRDP up to 3.20.0 ndr_read_uint8Array out-of-bounds write (GHSA-47v9-p4gp-w5ch / EUVD-2026-2674)
A vulnerability has been found in FreeRDP up to 3.20.0 and classified as critical. This impacts the function ndr_read_uint8Array. The manipulation leads to out-of-bounds write.
This vulnerability is documented as CVE-2026-22853. The attack can be initiated remotely. There is not any exploit available.
The affected component should be upgraded.
OSV
CVE-2026-22853: FreeRDP is a free implementation of the Remote Desktop Protocol
osv·2026-01-14·CVSS 6.8
CVE-2026-22853 [MEDIUM] CVE-2026-22853: FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-22853 freerdp: FreeRDP heap-buffer-overflow
bugzilla·2026-01-14·CVSS 6.8
CVE-2026-22853 [MEDIUM] CVE-2026-22853 freerdp: FreeRDP heap-buffer-overflow
CVE-2026-22853 freerdp: FreeRDP heap-buffer-overflow
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.
Discussion:
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10
Via RHSA-2026:3068 https://access.redhat.com/errata/RHSA-2026:3068
---
This issue has been addressed in the following products:
Red Hat Enterprise Linux 10.0 Extended Update Support
Via RHSA-2026:4121 https://access.redhat.com/errata/RHSA-2026:4121
---
This issue has been addressed in the following products:
Red Hat
Wiz
CVE-2026-22853 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 6.8
CVE-2026-22853 [MEDIUM] CVE-2026-22853 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-22853 :
NixOS vulnerability analysis and mitigation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.
Source : NVD
## 6.8
Score
Published January 14, 2026
Severity MEDIUM
CNA Score 6.8
Affected Technologies
NixOS
Rocky Linux
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 25.1
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
libfreerdp3-3
libuwac0-0
Sources
NVD
Alpine 3.10, 3.11,
https://github.com/FreeRDP/FreeRDP/releases/tag/3.20.1https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-47v9-p4gp-w5chhttps://access.redhat.com/errata/RHSA-2026:19033https://access.redhat.com/errata/RHSA-2026:3068https://access.redhat.com/errata/RHSA-2026:4121https://access.redhat.com/security/cve/CVE-2026-22853https://bugzilla.redhat.com/show_bug.cgi?id=2429647https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22853.json
2026-01-14
Published