Remote Desktop Protocol Vulnerability in FreeRDP by FreeRDP
CVE-2026-69159
5.4MEDIUM
What is CVE-2026-69159?
FreeRDP, an implementation of the Remote Desktop Protocol, is vulnerable due to improper verification of data during the decoding process. In versions prior to 3.29.0, the functions planar_decompress_plane_rle and planar_decompress_plane_rle_only do not adequately check if the source buffer contains the expected number of bytes as indicated by the control byte. This vulnerability allows attackers to execute crafted RDP server responses that can lead to client crashes and potential exposure of adjacent memory content, thereby escalating security risks. This issue is mitigated in version 3.29.0.
Affected Version(s)
FreeRDP < 3.29.0
