Junglewise Threat Intelligence

CVE-2026-44421: FreeRDP heap buffer overflow in gdi_CacheToSurface

CVE-2026-44421 · Severity: high · CVSS 8.8 · Published 2026-05-29

Technologies: FreeRDP. Vendors: FreeRDP.

Executive brief

FreeRDP is an open-source implementation of the Remote Desktop Protocol used to connect to remote computers. A vulnerability in the client software allows a malicious server to crash the user's connection or potentially execute unauthorized code on the user's computer. This occurs when the client connects to a compromised or malicious server while the RDPGFX feature is enabled.

Technical details

A heap-based buffer overflow exists in FreeRDP's gdi_CacheToSurface function within the RDPGFX pipeline. The vulnerability is caused by improper validation of destination rectangles; specifically, the code validates a rectangle that has been clamped to UINT16_MAX, but subsequently performs a memory copy using the original, unclamped width and height from the cache entry. An attacker-controlled RDP server can exploit this by sending crafted RDPGFX PDUs to trigger a large out-of-bounds heap write. This can result in a denial-of-service (client crash) or potential remote code execution on the client machine. The issue is fixed in version 3.26.0 by implementing bounds checks against the actual copy dimensions.

Affected products

  • FreeRDP FreeRDP < 3.26.0

Timeline

  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-05-29: disclosed: NVD publication date

References

Related threats