Heap Out-of-Bounds Read Vulnerability in FreeRDP by FreeRDP
CVE-2026-85090
5.3MEDIUM
What is CVE-2026-85090?
FreeRDP prior to version 3.31.0 experiences a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during the AVC444 chroma plane reconstruction process. An attacker operating a malicious RDP server can craft a specific RFX_AVC444_BITMAP_STREAM that triggers an out-of-bounds memory read beyond the allocated luma plane, potentially leading to unauthorized data access or crashes.
Affected Version(s)
FreeRDP 3.0.0 < 3.31.0
FreeRDP 3.31.0
