Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.9
CVE-2026-63633: FreeRDP Remote Desktop Protocol Client Heap Corruption
CVE-2026-63633 · published 15 days ago
Summary
FreeRDP, a free implementation of the Remote Desktop Protocol, has a bug that can cause a client to crash or run malicious code. This bug affects clients built with certain settings and connecting to a malicious RDP server. To fix this issue, update to version 3.28.0 or later.
What to do
- Update debian freerdp3 to version 3.28.0+dfsg-1.
- Update canonical freerdp3 to version 3.30.0+dfsg-0ubuntu0.24.04.1.
- Update canonical freerdp3 to version 3.30.0+dfsg-0ubuntu0.26.04.1.
Affected software
| Ecosystem | Vendor | Product | Affected versions |
|---|---|---|---|
| Debian:14 | debian | freerdp3 |
< 3.28.0+dfsg-1 Fix: upgrade to 3.28.0+dfsg-1
|
| Ubuntu:Pro:24.04:LTS | canonical | freerdp2 | All versions |
| Ubuntu:26.04:LTS | canonical | freerdp3 |
< 3.30.0+dfsg-0ubuntu0.26.04.1 Fix: upgrade to 3.30.0+dfsg-0ubuntu0.26.04.1
|
| – | freerdp | freerdp | < 3.28.0 |
| Debian:11 | debian | freerdp2 | All versions |
| Debian:12 | debian | freerdp2 | All versions |
| Debian:13 | debian | freerdp3 | All versions |
| Ubuntu:16.04:LTS | canonical | freerdp | All versions |
| Ubuntu:Pro:18.04:LTS | canonical | freerdp2 | All versions |
| Ubuntu:18.04:LTS | canonical | freerdp | All versions |
| Ubuntu:Pro:20.04:LTS | canonical | freerdp2 | All versions |
| Ubuntu:22.04:LTS | canonical | freerdp2 | All versions |
| Ubuntu:24.04:LTS | canonical | freerdp3 |
< 3.30.0+dfsg-0ubuntu0.24.04.1 Fix: upgrade to 3.30.0+dfsg-0ubuntu0.24.04.1
|
Original advisory text
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer ev...
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, freerdp_dsp_decode_opus in libfreerdp/codec/dsp.c calls Stream_EnsureRemainingCapacity on context->common.buffer even though opus_decode writes decoded PCM into the caller-supplied out stream. A malicious RDP server that negotiates WAVE_FORMAT_OPUS with a client built with WITH_OPUS enabled and WITH_DSP_FFMPEG disabled can make libopus write a large decoded frame beyond the 4096-byte StreamPool_Take destination used by channels/rdpsnd/client/rdpsnd_main.c. This can corrupt the client heap, crash the client, and may permit code execution. This issue is fixed in version 3.28.0.
References
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-72j9-356v-88xq x_refsource_CONFIRM
- https://github.com/FreeRDP/FreeRDP/pull/12993 x_refsource_MISC
- https://github.com/FreeRDP/FreeRDP/commit/0ed1f95d36913581cf31124f94eb5843d4263e... x_refsource_MISC
- https://github.com/FreeRDP/FreeRDP/releases/tag/3.28.0 x_refsource_MISC
- https://security-tracker.debian.org/tracker/CVE-2026-63633 Vendor Advisory
- https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/63xxx/CVE-2026-63633... Vendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2026-63633 Vendor Advisory
- https://ubuntu.com/security/CVE-2026-63633 Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2026-63633 Third Party Advisory
Severity
9.9
Critical
CVSS 4.0: 9.9 (OSV)
Exploitation
EPSS <1%
Type
CWE-122Heap-based Buffer Overflow
Timeline
Published19 Aug 2026
Updated3 Sep 2026
First seen19 Aug 2026
Sources
DEBIAN-CVE-2026-63633 · OSV
UBUNTU-CVE-2026-63633 · OSV
CVE-2026-63633 · OSV
GHSA-72j9-356v-88xq · GHSA
CVE-2026-63633 · NVD
CVE-2026-63633 · MITRE
Monitor software like this
Free during beta