Junglewise Threat Intelligence

CVE-2026-41521: neutrinolabs xrdp integer overflow in vnc-any mode

CVE-2026-41521 · Severity: high · CVSS 8.2 · Published 2026-07-20

Technologies: Neutrinolabs Xrdp. Vendors: Neutrinolabs.

Executive brief

xrdp is an open-source tool that allows users to remotely access Linux desktops. A security flaw in its VNC connection mode allows a malicious server to send specially crafted data that triggers a memory error. This could allow an attacker to crash the service or steal sensitive information from the system's memory.

Technical details

An integer overflow vulnerability exists in xrdp versions 0.10.6 and prior when processing screen update messages in the 'vnc-any' connection mode. A malicious remote VNC server can provide crafted image dimensions that cause an integer overflow during memory buffer size calculation, leading to an undersized heap allocation. When the system subsequently processes the image data using the original oversized parameters, it performs an out-of-bounds read. This can be exploited by an unauthenticated remote attacker to disclose sensitive heap memory or cause a process crash (DoS). The issue is fixed in version 0.10.6.1; as a mitigation, users can disable the [vnc-any] section in xrdp.ini.

Affected products

  • neutrinolabs xrdp <= 0.10.6

Timeline

  • 2026-07-02: advisory: GitHub Security Advisory published
  • 2026-07-06: patched: Version 0.10.6.1 released
  • 2026-07-20: disclosed: NVD publication date

References

Related threats