cbcvebase.

Debian Freerdp3 vulnerabilities

73 known vulnerabilities affecting debian/freerdp3.

Total CVEs
73
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH28MEDIUM33LOW4

Vulnerabilities

Page 1 of 4
CVE-2024-32039P2CRITICALCVSS 9.8fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2024
CVE-2024-32039 [CRITICAL] CVE-2024-32039: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c... FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients using a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to integer overflow and out-of-bounds write. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use `/gfx` options (e.g. deactivate with `/bpp:32` or `/rfx` as it is on by default). Scope: loca
debian
CVE-2026-31806P3CRITICALCVSS 9.3fixed in freerdp3 3.24.0+dfsg-1 (forky)2026
CVE-2026-31806 [CRITICAL] CVE-2026-31806: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, the gdi_surface_bits() function processes SURFACE_BITS_COMMAND messages sent by the RDP server. When the command is handled using NSCodec, the bmp.width and bmp.height values provided by the server are not properly validated against the actual desktop dimensions. A malicious RDP s
debian
CVE-2024-32040P3HIGHCVSS 8.1fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2024
CVE-2024-32040 [HIGH] CVE-2024-32040: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c... FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 and have connections to servers using the `NSC` codec are vulnerable to integer underflow. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, do not use the NSC codec (e.g. use `-nsc`). Scope: local bookworm: resolve
debian
CVE-2024-32458P3CRITICALCVSS 9.8fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2024
CVE-2024-32458 [CRITICAL] CVE-2024-32458: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c... FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use `/gfx` or `/rfx` modes (on by default, require server side support). Scope: local bookworm: resolved (fixed in 2.11.7+d
debian
CVE-2026-23531P2HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23531 [HIGH] CVE-2026-23531: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, in ClearCodec, when `glyphData` is present, `clear_decompress` calls `freerdp_image_copy_no_overlap` without validating the destination rectangle, allowing an out-of-bounds read/write via crafted RDPGFX surface updates. A malicious server can trigger a client‑side heap buffer
debian
CVE-2026-23530P2HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23530 [HIGH] CVE-2026-23530: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE decode. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap corruption with code‑execution ris
debian
CVE-2026-23532P2HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23532 [HIGH] CVE-2026-23532: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the FreeRDP client’s `gdi_SurfaceToSurface` path due to a mismatch between destination rectangle clamping and the actual copy size. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potenti
debian
CVE-2026-23534P3HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23534 [HIGH] CVE-2026-23534: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec bands decode path when crafted band coordinates allow writes past the end of the destination surface buffer. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap
debian
CVE-2024-32460P3HIGHCVSS 8.1fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2024
CVE-2024-32460 [HIGH] CVE-2024-32460: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based b... FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based based clients using `/bpp:32` legacy `GDI` drawing path with a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, use modern drawing paths (e.g. `/rfx` or `/gfx` options). The workaround requires s
debian
CVE-2026-22858P3MEDIUMCVSS 5.6fixed in freerdp3 3.20.2+dfsg-1 (forky)2026
CVE-2026-22858 [MEDIUM] CVE-2026-22858: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c <= 0 can be optimized into a simple c != 0 check. As a result, non-ASC
debian
CVE-2026-23883P2HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23883 [HIGH] CVE-2026-23883: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, `xf_Pointer_New` frees `cursorPixels` on failure, then `pointer_free` calls `xf_Pointer_Free` and frees it again, triggering ASan UAF. A malicious server can trigger a client‑side use after free, causing a crash (DoS) and potential heap corruption with code‑execution risk depe
debian
CVE-2024-32459P3CRITICALCVSS 9.8fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2024
CVE-2024-32459 [CRITICAL] CVE-2024-32459: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c... FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients and servers that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. No known workarounds are available. Scope: local bookworm: resolved (fixed in 2.11.7+dfsg1-6~deb12u1) bullseye: resolved (fixed
debian
CVE-2026-22852P3MEDIUMCVSS 6.8fixed in freerdp3 3.20.2+dfsg-1 (forky)2026
CVE-2026-22852 [MEDIUM] CVE-2026-22852: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client when processing Audio Input (AUDIN) format lists. audin_process_formats reuses callback->formats_count across multiple MSG_SNDIN_FORMATS PDUs and writes past the newly allocated formats array, caus
debian
CVE-2026-26965P3HIGHCVSS 8.8fixed in freerdp3 3.23.0+dfsg-1 (forky)2026
CVE-2026-26965 [HIGH] CVE-2026-26965: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, in the RLE planar decode path, `planar_decompress_plane_rle()` writes into `pDstData` at `((nYDst+y) * nDstStep) + (4*nXDst) + nChannel` without verifying that `(nYDst+nSrcHeight)` fits in the destination height or that `(nXDst+nSrcWidth)` fits in the destination stride. When
debian
CVE-2026-26955P3HIGHCVSS 8.8fixed in freerdp3 3.23.0+dfsg-1 (forky)2026
CVE-2026-26955 [HIGH] CVE-2026-26955: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not ca
debian
CVE-2026-23533P3HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23533 [HIGH] CVE-2026-23533: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the RDPGFX ClearCodec decode path when maliciously crafted residual data causes out-of-bounds writes during color output. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap co
debian
CVE-2026-23884P3HIGHCVSS 7.7fixed in freerdp3 3.21.0+dfsg-1 (forky)2026
CVE-2026-23884 [HIGH] CVE-2026-23884: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, offscreen bitmap deletion leaves `gdi->drawing` pointing to freed memory, causing UAF when related update packets arrive. A malicious server can trigger a client‑side use after free, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allo
debian
CVE-2024-32041P3CRITICALCVSS 9.8fixed in freerdp2 2.11.7+dfsg1-6~deb12u1 (bookworm)2024
CVE-2024-32041 [CRITICAL] CVE-2024-32041: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based c... FreeRDP is a free implementation of the Remote Desktop Protocol. FreeRDP based clients that use a version of FreeRDP prior to 3.5.0 or 2.11.6 are vulnerable to out-of-bounds read. Versions 3.5.0 and 2.11.6 patch the issue. As a workaround, deactivate `/gfx` (on by default, set `/bpp` or `/rfx` options instead. Scope: local bookworm: resolved (fixed in 2.11.7+df
debian
CVE-2026-22853P3MEDIUMCVSS 6.8fixed in freerdp3 3.20.2+dfsg-1 (forky)2026
CVE-2026-22853 [MEDIUM] CVE-2026-22853: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1. Scope: local bookworm: open bullseye: open
debian
CVE-2026-22854P3MEDIUMCVSS 6.8fixed in freerdp3 3.20.2+dfsg-1 (forky)2026
CVE-2026-22854 [MEDIUM] CVE-2026-22854: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap-buffer-overflow occurs in drive read when a server-controlled read length is used to read file data into an IRP output stream buffer without a hard upper bound, allowing an oversized read to overwrite heap memory. This vulnerability is fixed in 3.20.1. Scope: local bookworm:
debian
Debian Freerdp3 vulnerabilities | cvebase