Junglewise Threat Intelligence

CVE-2026-55564: FreeRDP heap buffer over-read in glyph cache bounds check

CVE-2026-55564 · Severity: medium · CVSS 5.4 · Published 2026-08-19

Technologies: FreeRDP. Vendors: FreeRDP.

Executive brief

FreeRDP is an open-source implementation of the Remote Desktop Protocol (RDP), widely used by enterprises to enable secure remote desktop access. A malicious RDP server can trigger an off-by-one error in the glyph cache, causing the client to read and dereference a pointer beyond the allocated cache array, leading to either client crashes (availability impact) or potential disclosure of adjacent heap memory (data exposure).

Technical details

The vulnerability is an off-by-one error in the glyph_cache_get function in libfreerdp/cache/glyph.c. The bounds check uses `index > cache->number` instead of `index >= cache->number`, allowing an attacker-controlled index value of 254 to pass validation when cache->number is also 254, resulting in an out-of-bounds read one position past the entries array. The attack is triggered via GLYPH_FRAGMENT_USE replay during RDP update processing on the client side, requiring no authentication or user interaction beyond connecting to a malicious RDP server. This can crash the RDP client or leak adjacent heap memory. The fix tightens the comparison to `>=` and was released in FreeRDP version 3.27.0.

Affected products

  • FreeRDP FreeRDP prior to 3.27.0

Timeline

  • 2026-08-19: disclosed
  • 2026-06-13: patched: Fix merged to master branch; released in version 3.27.0

References

Related threats