VYPR
Medium severity5.3OSV Advisory· Published Jul 20, 2026· Updated Jul 22, 2026

CVE-2026-55238

CVE-2026-55238

Description

xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficient length validation for specific capability sets. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed capability data. Due to missing bounds checks, the xrdp process may perform out-of-bounds memory reads, which can result in the termination of the service (Denial of Service). However, since xrdp forks a new process for each connection by default, an out-of-bounds read causing a process crash is unlikely to bring down the entire xrdp service. This issue has been fixed in version 0.10.6.1.

Affected products

4
  • Neutrinolabs/XrdpOSV3 versions
    v0.10.6.1-rc.1, v0.10.6, v0.10.5, …+ 2 more
    • (no CPE)range: v0.10.6.1-rc.1, v0.10.6, v0.10.5, …
    • cpe:2.3:a:neutrinolabs:xrdp:*:*:*:*:*:*:*:*range: <0.10.6.1
    • (no CPE)range: <=0.10.6
  • Xrdp/Xrdpllm-fuzzy
    Range: <=0.10.6

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.