Skip to content
VulniPulse
Advisory severityHigh8.8Red Hat Linux

High [CVE-2026-55194] Heap-buffer-overflow allows arbitrary code execution via crafted RPC response

This high-severity Red Hat Linux advisory covers CVE-2026-55194 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-55194 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written.

A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption.

This issue is fixed in version 3.27.0. A flaw was found in FreeRDP.

A remote attacker, specifically a malicious TS Gateway, can exploit a heap-buffer-overflow vulnerability by sending a specially crafted Remote Desktop Protocol (RDP) response. This occurs because the client incorrectly uses a smaller `alloc_hint` value instead of the actual `StubLength` for buffer capacity during response reassembly.

This allows attacker-controlled data to be written beyond the intended buffer, leading to a client crash and potentially enabling arbitrary code execution. This can result in client crashes or potential arbitrary code execution.

Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-120.

Affected versions
  • < 3.27.0

Official advisory · high-confidence parse· fetched 9 days ago·verify at source

Fixed versions
  • 3.27.0
  • freerdp-2:3.10.3-12.el10_2.10
  • freerdp-2:3.10.3-3.el10_0.16
  • freerdp-0:2.1.1-5.el7_9.12
  • freerdp-2:2.11.7-12.el8_10
  • freerdp-2:2.2.0-14.el8_4.3
  • freerdp-2:2.2.0-7.el8_6.12
  • freerdp-2:2.2.0-12.el8_8.11
  • freerdp-2:2.11.7-7.el9_8.6
  • freerdp-2:2.4.1-6.el9_2.12
  • freerdp-2:2.11.2-1.el9_4.11
  • freerdp-2:2.11.7-1.el9_6.13
  • RHSA-2026:61378
  • RHSA-2026:68706
  • RHSA-2026:68707
  • RHSA-2026:62571
  • RHSA-2026:65855
  • RHSA-2026:66281
  • RHSA-2026:66282
  • RHSA-2026:61379
  • RHSA-2026:71388
  • RHSA-2026:71390
  • RHSA-2026:71387

Official advisory · high-confidence parse· fetched 9 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • To mitigate this vulnerability, avoid connecting through untrusted TS Gateways (RD Gateways) or disable gateway parameters (such as omitting `/g:` in `xfreerdp`) to force direct RDP connections and bypass RPC response parsing.

Official advisory · high-confidence parse· fetched 9 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.