Junglewise Threat Intelligence

CVE-2026-31806: FreeRDP heap buffer overflow in gdi_surface_bits via NSCodec

CVE-2026-31806 · Severity: critical · CVSS 9.8 · Published 2026-03-13

Technologies: Red Hat Enterprise Linux, FreeRDP. Vendors: Red Hat, FreeRDP.

Executive brief

FreeRDP is an open-source tool used to connect to remote computers via the Remote Desktop Protocol (RDP). A critical security flaw allows a malicious RDP server to send specially crafted data that crashes the client or potentially allows the server to take control of the user's computer. This is particularly dangerous for users who connect to untrusted or compromised remote desktops, as it could lead to data theft or full system compromise.

Technical details

A heap-based buffer overflow exists in FreeRDP's 'gdi_surface_bits()' function when processing 'SURFACE_BITS_COMMAND' messages using NSCodec. The vulnerability stems from a lack of bounds checking where 'bmp.width' and 'bmp.height' values provided by a remote RDP server are not validated against the negotiated desktop dimensions ('gdi->width' and 'gdi->height'). While the code verifies if the destination offset is within bounds, it fails to ensure the entire bitmap rectangle fits within the allocated 'gdi->primary_buffer'. An attacker controlling a malicious RDP server can exploit this to overwrite adjacent heap memory with arbitrary pixel data, potentially leading to remote code execution (RCE). The issue is resolved in version 3.24.0 by limiting the copy area to the dimensions of the destination buffer.

Affected products

  • FreeRDP FreeRDP < 3.24.0
  • Red Hat Enterprise Linux 8, 10, 7 ELS

Timeline

  • 2026-03-13: advisory: GitHub Security Advisory published
  • 2026-03-13: patched: Fix committed to FreeRDP repository
  • 2026-04-23: advisory: Red Hat issued security advisory RHSA-2026:10076

References

Related threats