CVE-2026-23530
DOCUMENTATION: A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. This vulnerability occurs because the freerdpbitmapdecompress_planar function does not properly validate bitmap dimensions when decompressing planar bitmap data. A malicious server can exploit this by sending specially crafted bitmap data, leading to a client-side heap buffer overflow. This can cause a crash (Denial of Service) and potentially allow for arbitrary code execution on the client system.
STATEMENT: For this vulnerability to be exploited, a client must connect to a maliciously-configured server. Red Hat recommends that FreeRDP clients are only used to connect to trusted servers.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/security/cve/CVE-2026-23530
