FreeRDP是FreeRDP团队开源的一款开源的远程桌面协议(RDP)的实现。 FreeRDP 3.27.1之前版本存在缓冲区错误漏洞,该漏洞源于在使用非默认的/cache:codec:rfx选项启动客户端时,将桌面步幅和高度传递给RemoteFX解码,而仅在gdi_Bitmap_Decompress中为较小的DstWidth和DstHeight分配bitmap->data,可能导致恶意RDP服务器触发堆越界写入。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|
| CVE-2026-57157 | 6.5 MEDIUM | Out-of-bounds read in the camera device enumerator server (rdpecam) via unterminated Devic |
| CVE-2026-57156 | FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsing | |
| CVE-2026-57158 | FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-2353 |
No comments yet