Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.9

CVE-2026-63633: FreeRDP Remote Desktop Protocol Client Heap Corruption

CVE-2026-63633 · published 15 days ago
Summary

FreeRDP, a free implementation of the Remote Desktop Protocol, has a bug that can cause a client to crash or run malicious code. This bug affects clients built with certain settings and connecting to a malicious RDP server. To fix this issue, update to version 3.28.0 or later.

What to do
  • Update debian freerdp3 to version 3.28.0+dfsg-1.
  • Update canonical freerdp3 to version 3.30.0+dfsg-0ubuntu0.24.04.1.
  • Update canonical freerdp3 to version 3.30.0+dfsg-0ubuntu0.26.04.1.
Affected software
Ecosystem VendorProductAffected versions
Debian:14 debian freerdp3 < 3.28.0+dfsg-1
Fix: upgrade to 3.28.0+dfsg-1
Ubuntu:Pro:24.04:LTS canonical freerdp2 All versions
Ubuntu:26.04:LTS canonical freerdp3 < 3.30.0+dfsg-0ubuntu0.26.04.1
Fix: upgrade to 3.30.0+dfsg-0ubuntu0.26.04.1
– freerdp freerdp < 3.28.0
Debian:11 debian freerdp2 All versions
Debian:12 debian freerdp2 All versions
Debian:13 debian freerdp3 All versions
Ubuntu:16.04:LTS canonical freerdp All versions
Ubuntu:Pro:18.04:LTS canonical freerdp2 All versions
Ubuntu:18.04:LTS canonical freerdp All versions
Ubuntu:Pro:20.04:LTS canonical freerdp2 All versions
Ubuntu:22.04:LTS canonical freerdp2 All versions
Ubuntu:24.04:LTS canonical freerdp3 < 3.30.0+dfsg-0ubuntu0.24.04.1
Fix: upgrade to 3.30.0+dfsg-0ubuntu0.24.04.1
Original advisory text
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer ev...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM into the caller-supplied out stream. A malicious RDP server that negotiates WAVE_FORMAT_OPUS with a client built with WITH_OPUS enabled and WITH_DSP_FFMPEG disabled can make libopus write a large decoded frame beyond the 4096-byte StreamPool_Take destination used by channels/rdpsnd/client/rdpsnd_main.c. This can corrupt the client heap, crash the client, and may permit code execution. This issue is fixed in version 3.28.0.
Severity
9.9 Critical
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published19 Aug 2026
Updated3 Sep 2026
First seen19 Aug 2026
Monitor software like this
Free during beta