Junglewise Threat Intelligence

CVE-2026-40033: FreeRDP heap buffer overflow in gdi_CacheToSurface

CVE-2026-40033 · Severity: high · CVSS 8.8 · Published 2026-05-26

Technologies: FreeRDP. Vendors: FreeRDP.

Executive brief

FreeRDP is an open-source implementation of the Remote Desktop Protocol (RDP) used to connect to remote computers. A security flaw in the client software allows a malicious RDP server to corrupt the memory of the connecting user's computer. This could lead to the application crashing or, in more severe cases, allow the attacker to execute unauthorized code on the user's system.

Technical details

A heap-based buffer overflow (CWE-122) exists in the FreeRDP client's `gdi_CacheToSurface` function within the RDPGFX channel. The vulnerability is caused by a logic error where destination rectangle coordinates are validated after being clamped to `UINT16_MAX`, but the subsequent memory copy operation (`freerdp_image_copy_no_overlap`) uses the original, unclamped dimensions from the `cacheEntry`. An attacker controlling a malicious RDP server can send crafted RDPGFX PDUs with specific surface and cache dimensions to bypass bounds checks. This results in a large out-of-bounds write to heap memory, which can be leveraged for remote code execution or a denial-of-service (crash). The issue is patched in version 3.26.0.

Affected products

  • FreeRDP FreeRDP < 3.26.0

Timeline

  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-05-26: disclosed: CVE published to NVD

References

Related threats