Denial of Service Vulnerability in xrdp Open Source RDP Server
CVE-2026-54538
7.5HIGH
What is CVE-2026-54538?
An issue in xrdp, an open-source RDP server, allows unauthenticated remote attackers to exploit the software by sending specially crafted packets. This can cause the xrdp process to enter an infinite CPU-bound loop due to improper validation of the totalLength field within the RDP protocol control header. As a result, the xrdp service can become unavailable, leading to potential system-wide resource exhaustion when multiple malicious connections are initiated. This vulnerability was resolved in version 0.10.6.1.
Affected Version(s)
xrdp < 0.10.6.1
