Executive brief
FreeRDP is an open-source implementation of the Remote Desktop Protocol (RDP), widely used by enterprises to enable secure remote desktop access. A malicious RDP server can trigger an off-by-one error in the glyph cache, causing the client to read and dereference a pointer beyond the allocated cache array, leading to either client crashes (availability impact) or potential disclosure of adjacent heap memory (data exposure).
Technical details
The vulnerability is an off-by-one error in the glyph_cache_get function in libfreerdp/cache/glyph.c. The bounds check uses `index > cache->number` instead of `index >= cache->number`, allowing an attacker-controlled index value of 254 to pass validation when cache->number is also 254, resulting in an out-of-bounds read one position past the entries array. The attack is triggered via GLYPH_FRAGMENT_USE replay during RDP update processing on the client side, requiring no authentication or user interaction beyond connecting to a malicious RDP server. This can crash the RDP client or leak adjacent heap memory. The fix tightens the comparison to `>=` and was released in FreeRDP version 3.27.0.
Affected products
- FreeRDP FreeRDP prior to 3.27.0
Timeline
- 2026-08-19: disclosed
- 2026-06-13: patched: Fix merged to master branch; released in version 3.27.0