CVE-2026-55191
published 2026-08-19CVE-2026-55191: FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend…
PriorityP260critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.83%
56.1th percentile
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c with 32-bit multiplication in avc444_ensure_buffer. A malicious RDP server can supply surface dimensions for which piDstStride multiplied by padDstHeight wraps to a small nonzero value, causing winpr_aligned_recalloc to allocate an undersized buffer before YUV420CombineToYUV444 writes using the actual stride and rectangle dimensions. This can cause a client crash and may permit code execution through attacker-influenced heap corruption. This issue is fixed in version 3.27.0.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| freerdp | freerdp | < 3.27.0 | 3.27.0 |
| freerdp | freerdp | — | — |
| ubuntu | freerdp3 | — | — |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.7HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
vendor_redhat8.7HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
FreeRDP up to 3.26.x H.264 Codec libfreerdp/codec/h264.c avc444_ensure_buffer heap-based overflow
vuldb·2026-09-23·CVSS 9.8
CVE-2026-55191 [CRITICAL] FreeRDP up to 3.26.x H.264 Codec libfreerdp/codec/h264.c avc444_ensure_buffer heap-based overflow
A vulnerability was found in FreeRDP up to 3.26.x and classified as critical. This vulnerability affects the function avc444_ensure_buffer of the file libfreerdp/codec/h264.c of the component H.264 Codec. The manipulation results in heap-based buffer overflow.
This vulnerability is cataloged as CVE-2026-55191. The attack may be launched remotely. There is no exploit available.
It is suggested to upgrade the affected component.
Red Hat
FreeRDP: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation
vendor_redhat·2026-08-19·CVSS 8.7
CVE-2026-55191 [HIGH] CWE-787 FreeRDP: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation
FreeRDP: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c with 32-bit multiplication in avc444_ensure_buffer. A malicious RDP server can supply surface dimensions for which piDstStride multiplied by padDstHeight wraps to a small nonzero value, causing winpr_aligned_recalloc to allocate an undersized buffer before YUV420CombineToYUV444 writes using the actual stride and rectangle dimensions. This can cause a client crash and may permit code execution through attacker-influenced heap corruption. This issue is fixed in v
Ubuntu
FreeRDP vulnerabilities
vendor_ubuntu·2026-07-20
CVE-2026-33995 FreeRDP vulnerabilities
Title: FreeRDP vulnerabilities
Summary: Several security issues were fixed in FreeRDP.
It was discovered that FreeRDP contained multiple security issues. An
attacker could possibly use these issues to obtain sensitive information,
cause FreeRDP to crash, resulting in a denial of service, or execute
arbitrary code.
Instructions: This update uses a new upstream release, which includes additional bug
fixes. In general, a standard system update will make all the necessary
changes.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2026-55191 freerdp2: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation [fedora-all]
bugzilla·2026-08-24·CVSS 8.7
CVE-2026-55191 [HIGH] CVE-2026-55191 freerdp2: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation [fedora-all]
CVE-2026-55191 freerdp2: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c with 32-bit multiplication in avc444_ensure_buffer. A malicious RDP server can supply surface dimensions for which piDstStride multiplied by padDstHeight wraps to a small nonzero value, causing winpr_aligned_rec
Bugzilla
CVE-2026-55191 freerdp2: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation [epel-all]
bugzilla·2026-08-24·CVSS 8.7
CVE-2026-55191 [HIGH] CVE-2026-55191 freerdp2: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation [epel-all]
CVE-2026-55191 freerdp2: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation [epel-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c with 32-bit multiplication in avc444_ensure_buffer. A malicious RDP server can supply surface dimensions for which piDstStride multiplied by padDstHeight wraps to a small nonzero value, causing winpr_aligned_recal
Bugzilla
CVE-2026-55191 freerdp: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation [fedora-all]
bugzilla·2026-08-24·CVSS 8.7
CVE-2026-55191 [HIGH] CVE-2026-55191 freerdp: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation [fedora-all]
CVE-2026-55191 freerdp: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation [fedora-all]
Disclaimer: Community trackers are created by Red Hat Product Security team on a best effort basis. Package maintainers are required to ascertain if the flaw indeed affects their package, before starting the update process.
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c with 32-bit multiplication in avc444_ensure_buffer. A malicious RDP server can supply surface dimensions for which piDstStride multiplied by padDstHeight wraps to a small nonzero value, causing winpr_aligned_reca
Bugzilla
CVE-2026-55191 FreeRDP: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation
bugzilla·2026-08-19·CVSS 8.7
CVE-2026-55191 [HIGH] CVE-2026-55191 FreeRDP: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation
CVE-2026-55191 FreeRDP: FreeRDP: Arbitrary code execution via heap-buffer-overflow in AVC444 YUV buffer allocation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients that negotiate RDPGFX AVC444 with an H.264 decoder backend calculate the intermediate YUV444 allocation size in libfreerdp/codec/h264.c with 32-bit multiplication in avc444_ensure_buffer. A malicious RDP server can supply surface dimensions for which piDstStride multiplied by padDstHeight wraps to a small nonzero value, causing winpr_aligned_recalloc to allocate an undersized buffer before YUV420CombineToYUV444 writes using the actual stride and rectangle dimensions. This can cause a client crash and may permit code execution through attacker-influenced heap corruption. This issu
https://github.com/FreeRDP/FreeRDP/commit/97f40b9e766af375f4e41ac6a3f4397d708d249chttps://github.com/FreeRDP/FreeRDP/pull/12873https://github.com/FreeRDP/FreeRDP/releases/tag/3.27.0https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vx73-w5q6-7jqrhttps://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vx73-w5q6-7jqr
2026-08-19
Published