Out-of-Bounds Memory Read in xrdp RDP Server by Neutrino Labs
CVE-2026-55645

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
20 July 2026

What is CVE-2026-55645?

xrdp, an open-source RDP server, has a vulnerability in the processing of Client Control PDUs. It lacks sufficient length validation, allowing a remote, unauthenticated attacker to exploit this flaw by sending specially crafted and truncated Client Control PDUs. This could lead to out-of-bounds memory reads, potentially causing the service to terminate (resulting in Denial of Service). However, as xrdp forks a new process for each connection, a single process crash is unlikely to affect the overall service availability. The vulnerability has been addressed in version 0.10.6.1.

Affected Version(s)

xrdp < 0.10.6.1

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.