High [CVE-2026-55194] Heap-buffer-overflow allows arbitrary code execution via crafted RPC response
This high-severity Red Hat Linux advisory covers CVE-2026-55194 affecting Red Hat Enterprise Linux 10.0 Extended Update Support, Red Hat Enterprise Linux 7 Extended Lifecycle Support, Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support.
Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.
VulniPulse record published Record updated
Android app · Google Play
Monitor future Red Hat Linux CVEs from your phone.
Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.
Summary
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written.
A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption.
This issue is fixed in version 3.27.0. A flaw was found in FreeRDP.
A remote attacker, specifically a malicious TS Gateway, can exploit a heap-buffer-overflow vulnerability by sending a specially crafted Remote Desktop Protocol (RDP) response. This occurs because the client incorrectly uses a smaller `alloc_hint` value instead of the actual `StubLength` for buffer capacity during response reassembly.
This allows attacker-controlled data to be written beyond the intended buffer, leading to a client crash and potentially enabling arbitrary code execution. This can result in client crashes or potential arbitrary code execution.
Red Hat severity: Important — CVSS 8.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H). Weakness: CWE-120.
- < 3.27.0
Official advisory · high-confidence parse· fetched 9 days ago·verify at source
- 3.27.0
- freerdp-2:3.10.3-12.el10_2.10
- freerdp-2:3.10.3-3.el10_0.16
- freerdp-0:2.1.1-5.el7_9.12
- freerdp-2:2.11.7-12.el8_10
- freerdp-2:2.2.0-14.el8_4.3
- freerdp-2:2.2.0-7.el8_6.12
- freerdp-2:2.2.0-12.el8_8.11
- freerdp-2:2.11.7-7.el9_8.6
- freerdp-2:2.4.1-6.el9_2.12
- freerdp-2:2.11.2-1.el9_4.11
- freerdp-2:2.11.7-1.el9_6.13
- RHSA-2026:61378
- RHSA-2026:68706
- RHSA-2026:68707
- RHSA-2026:62571
- RHSA-2026:65855
- RHSA-2026:66281
- RHSA-2026:66282
- RHSA-2026:61379
- RHSA-2026:71388
- RHSA-2026:71390
- RHSA-2026:71387
Official advisory · high-confidence parse· fetched 9 days ago·verify at source
Mitigation checklist
- To mitigate this vulnerability, avoid connecting through untrusted TS Gateways (RD Gateways) or disable gateway parameters (such as omitting `/g:` in `xfreerdp`) to force direct RDP connections and bypass RPC response parsing.
Official advisory · high-confidence parse· fetched 9 days ago·verify at source
Discussion(0)
No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.
Sign in to join the discussion.