Executive brief
FreeRDP is a Remote Desktop Protocol client used to connect to Windows and other remote desktop systems. A malicious RDP server can send specially crafted video frames that cause the H.264 decoder to read beyond allocated memory buffers, potentially exposing sensitive client data in memory or crashing the application.
Technical details
The vulnerability is a buffer over-read in FreeRDP's H.264 video decoder (CVE-2026-55192). The codec backends fail to validate that decoded YUV frame dimensions match the negotiated RDPGFX surface dimensions, allowing a malicious RDP server to provide an AVC420 or AVC444 bitstream with a smaller decoded frame than expected. The YUV-to-RGB conversion path in libfreerdp/codec/h264.c then reads beyond the allocated decoder planes. This requires an attacker to control the RDP server and establish a connection to a vulnerable client. Exploitation can disclose client memory contents or crash the application. The fix was released in FreeRDP 3.27.0 and adds explicit frame size validation before YUV conversion.
Affected products
- FreeRDP FreeRDP prior to 3.27.0
Timeline
- 2026-08-19: disclosed
- 2026-06-11: patched: Fixed in version 3.27.0