Executive brief
FreeRDP is an open-source tool used to connect to remote computers via the Remote Desktop Protocol (RDP). A security flaw allows a malicious RDP server to take control of a user's computer if the user attempts to connect to it. This could result in the theft of sensitive data, unauthorized access to the user's local system, or the installation of malware.
Technical details
A heap-based buffer overflow exists in FreeRDP clients using the GDI surface pipeline (e.g., xfreerdp) due to missing bounds validation in the `gdi_SurfaceCommand_ClearCodec()` handler. The function fails to call `is_within_surface()` to validate attacker-controlled destination rectangle coordinates (`cmd->left` and `cmd->top`) against the target surface dimensions. When processing ClearCodec surface commands with `subcodecId=1` (NSCodec), these unchecked offsets reach `freerdp_image_copy_no_overlap()`, leading to an out-of-bounds write. This OOB write can corrupt adjacent `gdiGfxSurface` structures, specifically the `codecs*` pointer, enabling an indirect function pointer call and full instruction pointer (RIP) control. The issue is patched in version 3.23.0.
Affected products
- FreeRDP FreeRDP < 3.23.0
- Red Hat Enterprise Linux 8, 10, 10.0 EUS, 10.2 EUS, 7 ELS
Timeline
- 2026-02-25: advisory: GitHub Security Advisory GHSA-mr6w-ch7c-mqqj published
- 2026-02-25: patched: Fix committed to FreeRDP repository
- 2026-05-19: patched: Red Hat released security updates for RHEL 10
References
- https://github.com/FreeRDP/FreeRDP/commit/7d8fdce2d0ef337cb86cb37fc0c436c905e04d77
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mr6w-ch7c-mqqj
- https://access.redhat.com/errata/RHSA-2026:19033
- https://access.redhat.com/errata/RHSA-2026:5936
- https://access.redhat.com/errata/RHSA-2026:5939
- https://access.redhat.com/errata/RHSA-2026:6004
- https://access.redhat.com/errata/RHSA-2026:6005