Critical severity9.8NVD Advisory· Published May 29, 2026· Updated Jul 29, 2026
CVE-2026-45700
CVE-2026-45700
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/planar.c, freerdp_bitmap_decompress_planar() validates the X destination coordinate nXDst against the caller-provided destination stride (nDstStep) even when it is writing into the internal temp buffer pTempData. An attacker can bypass the check with a large nDstStep and a large nXDst, causing planar_decompress_plane_rle() to write past the end of pTempData. This vulnerability is fixed in 3.26.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
13- osv-coords10 versionspkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Server%2016.0pkg:rpm/suse/freerdp&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20applications%2016.0pkg:rpm/opensuse/freerdp&distro=openSUSE%20Tumbleweedpkg:rpm/almalinux/freerdp-serverpkg:rpm/almalinux/libwinprpkg:rpm/opensuse/freerdp&distro=openSUSE%20Leap%2016.0pkg:rpm/almalinux/freerdppkg:rpm/almalinux/freerdp-develpkg:rpm/almalinux/freerdp-libspkg:rpm/almalinux/libwinpr-devel
< 3.26.0-160000.1.1+ 9 more
- (no CPE)range: < 3.26.0-160000.1.1
- (no CPE)range: < 3.26.0-160000.1.1
- (no CPE)range: < 3.26.0-3.1
- (no CPE)range: < 2:3.10.3-12.el10_2.6
- (no CPE)range: < 2:3.10.3-12.el10_2.6
- (no CPE)range: < 3.26.0-160000.1.1
- (no CPE)range: < 2:3.10.3-12.el10_2.6
- (no CPE)range: < 2:3.10.3-12.el10_2.6
- (no CPE)range: < 2:3.10.3-12.el10_2.6
- (no CPE)range: < 2:3.10.3-12.el10_2.6
Patches
Vulnerability mechanics
References
15- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mpxh-8fq3-x8mhnvdExploitMitigationVendor Advisory
- access.redhat.com/errata/RHSA-2026:36203nvd
- access.redhat.com/errata/RHSA-2026:37207nvd
- access.redhat.com/errata/RHSA-2026:38501nvd
- access.redhat.com/errata/RHSA-2026:46383nvd
- access.redhat.com/errata/RHSA-2026:46384nvd
- access.redhat.com/errata/RHSA-2026:46388nvd
- access.redhat.com/errata/RHSA-2026:46389nvd
- access.redhat.com/errata/RHSA-2026:46393nvd
- access.redhat.com/errata/RHSA-2026:47048nvd
- access.redhat.com/errata/RHSA-2026:47049nvd
- access.redhat.com/errata/RHSA-2026:47201nvd
- access.redhat.com/security/cve/CVE-2026-45700nvd
- bugzilla.redhat.com/show_bug.cginvd
- security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-45700.jsonnvd
News mentions
0No linked articles in our index yet.