CVE-2026-23532
DOCUMENTATION: A flaw was found in FreeRDP. A malicious server can exploit a client-side heap buffer overflow vulnerability in the gdi_SurfaceToSurface path. This vulnerability, caused by a mismatch in memory handling, can lead to a crash (Denial of Service) of the client application. Furthermore, it carries a risk of heap corruption, which could potentially enable arbitrary code execution on the affected system.
STATEMENT: For this vulnerability to be exploited, a client must connect to a maliciously-configured server. Red Hat recommends that FreeRDP clients are only used to connect to trusted servers.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://access.redhat.com/security/cve/CVE-2026-23532
