Critical severity9.8NVD Advisory· Published Aug 19, 2026· Updated Sep 24, 2026
CVE-2026-55194
CVE-2026-55194
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.
Affected products
8- osv-coords7 versionspkg:rpm/almalinux/libwinprpkg:rpm/almalinux/freerdppkg:rpm/opensuse/freerdp&distro=openSUSE%20Tumbleweedpkg:rpm/almalinux/freerdp-serverpkg:rpm/almalinux/freerdp-develpkg:rpm/almalinux/freerdp-libspkg:rpm/almalinux/libwinpr-devel
< 2:3.10.3-12.el10_2.10+ 6 more
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 3.27.1-1.1
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
- (no CPE)range: < 2:3.10.3-12.el10_2.10
Patches
Vulnerability mechanics
References
4- github.com/FreeRDP/FreeRDP/commit/9f2da52c2341cc14a96ad12e69c5b83d0bcd8b5anvdPatch
- github.com/FreeRDP/FreeRDP/pull/12873nvdIssue TrackingPatch
- github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9gxm-3mf5-f5cxnvdExploitMitigationVendor Advisory
- github.com/FreeRDP/FreeRDP/releases/tag/3.27.0nvdRelease Notes
News mentions
1- FreeRDP: Ten Vulnerabilities Disclosed Together, Ranging from Medium to High SeverityVypr Intelligence · Aug 19, 2026