VYPR
High severity8.8OSV Advisory· Published Jul 20, 2026· Updated Jul 23, 2026

CVE-2026-44178

CVE-2026-44178

Description

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a heap-based buffer overflow vulnerability within the virtual channel forwarding mechanism. When forwarding data from a remote client to the internal channel server, the xrdp process utilizes a fixed-size buffer without adequate bounds checking on the incoming payload. An authenticated remote attacker can exploit this flaw by sending a specially crafted virtual channel message that exceeds the buffer capacity, leading to heap memory corruption. This may result in a denial of service or the execution of arbitrary code with the privileges of the xrdp process. This issue has been fixed in version 0.10.6.1.

Affected products

3
  • Neutrinolabs/XrdpOSV3 versions
    v0.10.6.1-rc.1, v0.10.6, v0.10.5, …+ 2 more
    • (no CPE)range: v0.10.6.1-rc.1, v0.10.6, v0.10.5, …
    • cpe:2.3:a:neutrinolabs:xrdp:*:*:*:*:*:*:*:*range: <0.10.6.1
    • (no CPE)range: <=0.10.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.