cbcvebase.

Debian Freerdp3 vulnerabilities

73 known vulnerabilities affecting debian/freerdp3.

Total CVEs
73
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL7HIGH28MEDIUM33LOW4

Vulnerabilities

Page 4 of 4
CVE-2026-26986P3MEDIUMCVSS 5.5fixed in freerdp3 3.23.0+dfsg-1 (forky)2026
CVE-2026-26986 [MEDIUM] CVE-2026-26986: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, `rail_window_free` dereferences a freed `xfAppWindow` pointer during `HashTable_Free` cleanup because `xf_rail_window_common` calls `free(appWindow)` on title allocation failure without first removing the entry from the `railWindows` hash table, leaving a dangling pointer th
debian
CVE-2026-31884P3MEDIUMCVSS 6.5fixed in freerdp3 3.24.0+dfsg-1 (forky)2026
CVE-2026-31884 [MEDIUM] CVE-2026-31884: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, division by zero in MS-ADPCM and IMA-ADPCM decoders when nBlockAlign is 0, leading to a crash. In libfreerdp/codec/dsp.c, both ADPCM decoders use size % block_size where block_size = context->common.format.nBlockAlign. The nBlockAlign value comes from the Server Audio Formats PDU on
debian
CVE-2026-33977P3MEDIUMCVSS 6.9fixed in freerdp3 3.24.2+dfsg-1 (forky)2026
CVE-2026-33977 [MEDIUM] CVE-2026-33977: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a malicious RDP server can crash the FreeRDP client by sending audio data in IMA ADPCM format with an invalid initial step index value (>= 89). The unvalidated step index is read directly from the network and used to index into a 89-entry lookup table, triggering a WINPR_ASS
debian
CVE-2026-33985P4MEDIUMCVSS 5.9fixed in freerdp3 3.24.2+dfsg-1 (forky)2026
CVE-2026-33985 [MEDIUM] CVE-2026-33985: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, pixel data from adjacent heap memory is rendered to screen, potentially leaking sensitive data to the attacker. This issue has been patched in version 3.24.2. Scope: local bookworm: open bullseye: open
debian
CVE-2026-27015P4MEDIUMCVSS 5.0fixed in freerdp3 3.23.0+dfsg-1 (forky)2026
CVE-2026-27015 [MEDIUM] CVE-2026-27015: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a missing bounds check in `smartcard_unpack_read_size_align()` (`libfreerdp/utils/smartcard_pack.c:1703`) allows a malicious RDP server to crash the FreeRDP client via a reachable `WINPR_ASSERT` → `abort()`. The crash occurs in upstream builds where `WITH_VERBOSE_WINPR_ASSER
debian
CVE-2026-33983P4MEDIUMCVSS 6.5fixed in freerdp3 3.24.2+dfsg-1 (forky)2026
CVE-2026-33983 [MEDIUM] CVE-2026-33983: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, progressive_decompress_tile_upgrade() detects a mismatch via progressive_rfx_quant_cmp_equal() but only emits WLog_WARN, execution continues. The wrapped value (247) is used as a shift exponent, causing undefined behavior and an approximately 80 billion iteration loop (CPU D
debian
CVE-2026-33952P4MEDIUMCVSS 6.0fixed in freerdp3 3.24.2+dfsg-1 (forky)2026
CVE-2026-33952 [MEDIUM] CVE-2026-33952: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, an unvalidated auth_length field read from the network triggers a WINPR_ASSERT() failure in rts_read_auth_verifier_no_checks(), causing any FreeRDP client connecting through a malicious RDP Gateway to crash with SIGABRT. This is a pre-authentication denial of service affecti
debian
CVE-2026-22851P4MEDIUMCVSS 6.9fixed in freerdp3 3.20.2+dfsg-1 (forky)2026
CVE-2026-22851 [MEDIUM] CVE-2026-22851: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a race condition between the RDPGFX dynamic virtual channel thread and the SDL render thread leads to a heap use-after-free. Specifically, an escaped pointer to sdl->primary (SDL_Surface) is accessed after it has been freed during RDPGFX ResetGraphics handling. This vulnerability is
debian
CVE-2026-26271P4MEDIUMCVSS 5.5fixed in freerdp3 3.23.0+dfsg-1 (forky)2026
CVE-2026-26271 [MEDIUM] CVE-2026-26271: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a buffer overread in `freerdp_image_copy_from_icon_data()` (libfreerdp/codec/color.c) can be triggered by crafted RDP Window Icon (TS_ICON_INFO) data. The bug is reachable over the network when a client processes icon data from an RDP server (or from a man-in-the-middle). Ve
debian
CVE-2026-33995P4MEDIUMCVSS 5.3fixed in freerdp3 3.24.2+dfsg-1 (forky)2026
CVE-2026-33995 [MEDIUM] CVE-2026-33995: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, a double-free vulnerability in kerberos_AcceptSecurityContext() and kerberos_InitializeSecurityContextA() (WinPR, winpr/libwinpr/sspi/Kerberos/kerberos.c) can cause a crash in any FreeRDP clients on systems where Kerberos and/or Kerberos U2U is configured (Samba AD member, o
debian
CVE-2026-33987P4HIGHCVSS 7.1fixed in freerdp3 3.24.2+dfsg-1 (forky)2026
CVE-2026-33987 [HIGH] CVE-2026-33987: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to versio... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.24.2, in persistent_cache_read_entry_v3() in libfreerdp/cache/persistent.c, persistent->bmpSize is updated before winpr_aligned_recalloc(). If realloc fails, bmpSize is inflated while bmpData points to the old buffer. This issue has been patched in version 3.24.2. Scope: local bookw
debian
CVE-2025-4478P4LOWCVSS 6.5fixed in freerdp3 3.15.0+dfsg-2.1 (forky)2025
CVE-2025-4478 [MEDIUM] CVE-2025-4478: freerdp2 - A flaw was found in the FreeRDP used by Anaconda's remote install feature, where... A flaw was found in the FreeRDP used by Anaconda's remote install feature, where a crafted RDP packet could trigger a segmentation fault. This issue causes the service to crash and remain defunct, resulting in a denial of service. It occurs pre-boot and is likely due to a NULL pointer dereference. Rebooting is required to recover the system. Scope: local bookworm:
debian
CVE-2026-29776P4LOWCVSS 3.1fixed in freerdp3 3.24.0+dfsg-1 (forky)2026
CVE-2026-29776 [LOW] CVE-2026-29776: freerdp2 - FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0... FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.24.0, Integer Underflow in update_read_cache_bitmap_order Function of FreeRDP's Core Library This vulnerability is fixed in 3.24.0. Scope: local bookworm: open bullseye: open
debian
Debian Freerdp3 vulnerabilities | cvebase