Remote Desktop Protocol Vulnerability in FreeRDP by FreeRDP
CVE-2026-55191
8.7HIGH
What is CVE-2026-55191?
FreeRDP clients prior to version 3.27.0 are affected by a vulnerability that occurs when negotiating RDPGFX AVC444 with an H.264 decoder backend. The flaw arises from the calculation of intermediate YUV444 allocation sizes, where faulty multiplication leads to an undersized buffer allocation. An attacker controlling an RDP server can exploit this vulnerability by supplying specific surface dimensions, potentially resulting in crashes of the client application or enabling remote code execution via heap corruption. This issue has been resolved in version 3.27.0.
Affected Version(s)
FreeRDP < 3.27.0
