Executive brief
FreeRDP is an open-source tool used to connect to remote computers via the Remote Desktop Protocol. A security flaw in the client software allows a malicious server to trigger a memory overflow on the user's computer. This could lead to the application crashing or, in more severe cases, allow the attacker to execute unauthorized code on the user's system.
Technical details
A heap-based buffer overflow exists in FreeRDP's `gdi_SurfaceToSurface` function within `libfreerdp/gdi/gfx.c`. The vulnerability is caused by a logic error where the destination rectangle is clamped using `MAX_UINT16`, but the subsequent `freerdp_image_copy` operation uses the original, unclamped width and height values. An attacker controlling a malicious RDP server can send a specially crafted SurfaceToSurface PDU that exceeds surface boundaries, leading to an out-of-bounds write. This can result in a denial of service (crash) or potential heap corruption leading to arbitrary code execution. The issue is addressed in version 3.21.0.
Affected products
- FreeRDP FreeRDP < 3.21.0
Timeline
- 2026-01-19: advisory
- 2026-01-19: patched
References
- https://github.com/FreeRDP/FreeRDP/blob/38514dfa5813aa945a86cfbcec279033f8394468/libfreerdp/gdi/gfx.c
- https://github.com/FreeRDP/FreeRDP/releases/tag/3.21.0
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-fq8c-87hj-7gvr
- https://access.redhat.com/errata/RHSA-2026:2048
- https://access.redhat.com/errata/RHSA-2026:2081
- https://access.redhat.com/errata/RHSA-2026:2222
- https://access.redhat.com/errata/RHSA-2026:2714