High severity8.8NVD Advisory· Published Aug 19, 2026· Updated Sep 29, 2026
CVE-2026-55193
CVE-2026-55193
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, FreeRDP clients using TS Gateway accept a server-controlled max_xmit_frag value in libfreerdp/core/gateway/rpc_bind.c without bounding it to the 4088-byte ReceiveFragment allocation. A malicious gateway can advertise 65535 and then send a response fragment of the same length, causing rpc_channel_read in libfreerdp/core/gateway/rpc.c to write up to 65535 bytes into the smaller ReceiveFragment buffer. This can crash the client and may permit code execution through attacker-controlled heap corruption. This issue is fixed in version 3.27.0.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8- osv-coords7 versionspkg:rpm/almalinux/freerdppkg:rpm/almalinux/freerdp-develpkg:rpm/almalinux/freerdp-libspkg:rpm/almalinux/freerdp-serverpkg:rpm/almalinux/libwinprpkg:rpm/almalinux/libwinpr-develpkg:rpm/opensuse/freerdp&distro=openSUSE%20Tumbleweed
< 2:2.11.7-7.el9_8.7+ 6 more
- (no CPE)range: < 2:2.11.7-7.el9_8.7
- (no CPE)range: < 2:2.11.7-7.el9_8.7
- (no CPE)range: < 2:2.11.7-7.el9_8.7
- (no CPE)range: < 2:3.10.3-12.el10_2.11
- (no CPE)range: < 2:2.11.7-7.el9_8.7
- (no CPE)range: < 2:2.11.7-7.el9_8.7
- (no CPE)range: < 3.27.1-1.1
Patches
Vulnerability mechanics
References
4- github.com/FreeRDP/FreeRDP/commit/a863ef1cf1cdabf9019280e5658f806e73bb50e8nvdPatch
- github.com/FreeRDP/FreeRDP/pull/12873nvdIssue TrackingPatch
- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-7rp4-66mc-j9vxnvdExploitVendor Advisory
- github.com/FreeRDP/FreeRDP/releases/tag/3.27.0nvdRelease Notes
News mentions
1- FreeRDP: Ten Vulnerabilities Disclosed Together, Ranging from Medium to High SeverityVypr Intelligence · Aug 19, 2026