CVE-2026-44178
published 2026-07-20CVE-2026-44178: xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding…
PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.88%
57.5th percentile
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp process utilizes a fixed-size buffer without adequate bounds checking on the incoming payload. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity, leading to heap memory corruption. This may result in a denial of service or the execution of arbitrary code with the privileges of the xrdp process. This issue has been fixed in version 0.10.6.1.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| neutrinolabs | xrdp | < 0.10.6.1 | 0.10.6.1 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No advisories linked to this vulnerability.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding [fedora-all]
bugzilla·2026-07-20·CVSS 8.8
CVE-2026-44178 [HIGH] CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding [fedora-all]
CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp process utilizes a fixed-size buffer without adequate bounds checking on the incoming payload. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity,
Bugzilla
CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding
bugzilla·2026-07-20·CVSS 8.8
CVE-2026-44178 [HIGH] CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding
CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp process utilizes a fixed-size buffer without adequate bounds checking on the incoming payload. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity, leading to heap memory corruption. This may result in a denial of service or the execution of arbitrary code with the privileges of the xrdp process. This issue has been fixed in version 0.10.6.1.
Bugzilla
CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding [epel-all]
bugzilla·2026-07-20·CVSS 8.8
CVE-2026-44178 [HIGH] CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding [epel-all]
CVE-2026-44178 xrdp: heap-based buffer overflow in virtual channel forwarding [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp process utilizes a fixed-size buffer without adequate bounds checking on the incoming payload. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity, le
2026-07-20
Published