Heap Out-of-Bounds Read Vulnerability in xrdp RDP Server
CVE-2026-44978
What is CVE-2026-44978?
The xrdp RDP server versions up to 0.10.6 are susceptible to a heap out-of-bounds read vulnerability that manifests under specific configurations. When the security layer is set to 'security_layer=negotiate' or 'security_layer=rdp', combined with the crypto level change to 'crypt_level=fips', the server fails to validate the FIPS padding length in incoming packets. This oversight can enable an unauthenticated remote attacker to execute a denial of service (DoS) attack by sending a maliciously crafted FIPS-protected PDU, leading to potential process crashes. Although this vulnerability primarily causes isolated process incidents due to xrdp's architecture of forking new processes for each connection, it remains vital for users to upgrade to version 0.10.6.1 to mitigate these risks.
Affected Version(s)
xrdp < 0.10.6.1
