CVE-2026-25941
published 2026-02-25CVE-2026-25941: FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an…
PriorityP343high8.1CVSS 3.1
AVNACLPRNUIRSUCHINAH
EPSS
0.28%
20.5th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory by sending a crafted WIRE_TO_SURFACE_2 PDU with a `bitmapDataLength` value larger than the actual data in the packet. This can lead to information disclosure or client crashes when a user connects to a malicious server. Versions 2.11.8 and 3.23.0 fix the issue.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | freerdp2 | < freerdp3 3.23.0+dfsg-1 (forky) | freerdp3 3.23.0+dfsg-1 (forky) |
| debian | freerdp3 | < freerdp3 3.23.0+dfsg-1 (forky) | freerdp3 3.23.0+dfsg-1 (forky) |
| freerdp | freerdp | — | — |
| freerdp | freerdp | — | — |
| freerdp | freerdp | >= 2.0.0 < 2.11.8 | 2.11.8 |
| freerdp | freerdp | >= 3.0.0 < 3.23.0 | 3.23.0 |
CVSS provenance
nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:H
osv8.1HIGH
vendor_debian4.3MEDIUM
vendor_redhat4.3MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2026-03-18
CVE-2026-25954 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP incorrectly handled certain RDP packets. A
remote attacker could use this issue to cause FreeRDP to crash, resulting
in a denial of service, or possibly execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
freerdp: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel
vendor_redhat·2026-02-25·CVSS 4.3
CVE-2026-25941 [MEDIUM] CWE-130 freerdp: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel
freerdp: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory by sending a crafted WIRE_TO_SURFACE_2 PDU with a `bitmapDataLength` value larger than the actual data in the packet. This can lead to information disclosure or client crashes when a user connects to a malicious server. Versions 2.11.8 and 3.23.0 fix the issue.
A flaw was found in the FreeRDP client. A malicious Remote Desktop Protocol (RDP) server can exploit an out-of-bounds read vulnerability in
Debian
CVE-2026-25941: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the...
vendor_debian·2026·CVSS 4.3
CVE-2026-25941 [MEDIUM] CVE-2026-25941: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the...
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory by sending a crafted WIRE_TO_SURFACE_2 PDU with a `bitmapDataLength` value larger than the actual data in the packet. This can lead to information disclosure or client crashes when a user connects to a malicious server. Versions 2.11.8 and 3.23.0 fix the issue.
Scope: local
bookworm: open
bullseye: open
OSV
CVE-2026-25941: FreeRDP is a free implementation of the Remote Desktop Protocol
osv·2026-02-25·CVSS 8.1
CVE-2026-25941 [HIGH] CVE-2026-25941: FreeRDP is a free implementation of the Remote Desktop Protocol
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory by sending a crafted WIRE_TO_SURFACE_2 PDU with a `bitmapDataLength` value larger than the actual data in the packet. This can lead to information disclosure or client crashes when a user connects to a malicious server. Versions 2.11.8 and 3.23.0 fix the issue.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-25941 freerdp: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel
bugzilla·2026-02-25·CVSS 8.1
CVE-2026-25941 [HIGH] CVE-2026-25941 freerdp: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel
CVE-2026-25941 freerdp: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel
FreeRDP is a free implementation of the Remote Desktop Protocol. Versions on the 2.x branch prior to to 2.11.8 and on the 3.x branch prior to 3.23.0 have an out-of-bounds read vulnerability in the FreeRDP client's RDPGFX channel that allows a malicious RDP server to read uninitialized heap memory by sending a crafted WIRE_TO_SURFACE_2 PDU with a `bitmapDataLength` value larger than the actual data in the packet. This can lead to information disclosure or client crashes when a user connects to a malicious server. Versions 2.11.8 and 3.23.0 fix the issue.
Bugzilla
CVE-2026-25941 freerdp2: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel [fedora-42]
bugzilla·2026-02-25·CVSS 8.1
CVE-2026-25941 [HIGH] CVE-2026-25941 freerdp2: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel [fedora-42]
CVE-2026-25941 freerdp2: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This message is a reminder that Fedora Linux 42 is nearing its end of life.
Fedora will stop maintaining and issuing updates for Fedora Linux 42 on 2026-05-13.
It is Fedora's policy to close all bug reports from releases that are no longer
maintained. At that time this bug will be closed as EOL if it remains open with a
'version' of '42'.
Package Maintainer: If you wish for this bug to remain open because you
plan to fix it in a c
Bugzilla
CVE-2026-25941 freerdp: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel [fedora-42]
bugzilla·2026-02-25·CVSS 8.1
CVE-2026-25941 [HIGH] CVE-2026-25941 freerdp: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel [fedora-42]
CVE-2026-25941 freerdp: FreeRDP: Information disclosure or client crash via out-of-bounds read in RDPGFX channel [fedora-42]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
Discussion:
This bug is already fixed in a published Bodhi update.
---
FEDORA-2026-53fe996a57 (freerdp-3.23.0-1.fc42) has been submitted as an update to Fedora 42.
https://bodhi.fedoraproject.org/updates/FEDORA-2026-53fe996a57
Wiz
CVE-2026-25941 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 4.3
CVE-2026-25941 [MEDIUM] CVE-2026-25941 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2026-25941 :
NixOS vulnerability analysis and mitigation
bitmapDataLength
Source : NVD
## 8.1
Score
Published February 25, 2026
Severity HIGH
CNA Score 4.3
Affected Technologies
NixOS
Wolfi
Has Public Exploit Yes
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 27.8
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
freerdp2
freerdp-devel
Sources
NVD
Alpine 3.11, 3.12, 3.13, 3.14, 3.15, 3.16, 3.17, 3.18, 3.19, 3.20, 3.21, 3.22, 3.23, edge Severity HIGH Has Fix Added at: Mar 02, 2026
Chainguard No Fix Added at: Mar 02, 2026
Debian 11, 13 Severity HIGH No Fix Added at: Mar 02, 2026
Debian 12 Severity MEDIUM No Fix Added at: Mar 02, 2026
Debian 14 Severity HIGH Has Fix Added
2026-02-25
Published