CVE detail
CVE-2026-26955
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.23.0, a malicious RDP server can trigger a heap buffer overflow in FreeRDP clients using the GDI surface pipeline (e.g., `xfreerdp`) by sending an RDPGFX ClearCodec surface command with an out-of-bounds destination rectangle. The `gdi_SurfaceCommand_ClearCodec()` handler does not call `is_within_surface()` to validate the command rectangle against the destination surface dimensions, allowing attacker-controlled `cmd->left`/`cmd->top` (and subcodec rectangle offsets) to reach image copy routines that write into `surface->data` without bounds enforcement. The OOB write corrupts an adjacent `gdiGfxSurface` struct's `codecs*` pointer with attacker-controlled pixel data, and corruption of `codecs*` is sufficient to reach an indirect function pointer call (`NSC_CONTEXT.decode` at `nsc.c:500`) on a subsequent codec command — full instruction pointer (RIP) control demonstrated in exploitability harness. Users should upgrade to version 3.23.0 to receive a patch.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 30.0 · diversity 13.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
19 source links · newest first
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-26955.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comFeb 25, 2026, 9:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2443132bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/security/cve/CVE-2026-26955access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:7292access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6764access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6712access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6665access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6616access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6396access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6395access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6385access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6384access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6005access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:6004access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:5939access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:5936access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM - https://access.redhat.com/errata/RHSA-2026:19033access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comFeb 25, 2026, 9:16 PM No excerpt available.
Exploitgithub.comFeb 25, 2026, 9:16 PMNo excerpt available.
Exploitgithub.comFeb 25, 2026, 9:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-53016CVSS 7.8 · High
In the Linux kernel, the following vulnerability has been resolved: crypto: ccp - copy IV using skcipher ivsize AF_ALG rfc3686-ctr-aes-ccp requests pass an 8-byte IV to the driv…
- CVE-2026-31607CVSS 9.8 · Critical
In the Linux kernel, the following vulnerability has been resolved: usbip: validate number_of_packets in usbip_pack_ret_submit() When a USB/IP client receives a RET_SUBMIT respo…
- CVE-2026-1837CVSS 8.7 · High
A specially-crafted file can cause libjxl's decoder to write pixel data to uninitialized unallocated memory. Soon after that data from another uninitialized unallocated region is…
- CVE-2025-23319CVSS 8.1 · High
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write by sending a request. A s…
- CVE-2025-23318CVSS 8.1 · High
NVIDIA Triton Inference Server for Windows and Linux contains a vulnerability in the Python backend, where an attacker could cause an out-of-bounds write. A successful exploit of…
- CVE-2024-24851CVSS 7.5 · High
A heap-based buffer overflow vulnerability exists in the Programming Software Connection FiBurn functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network pac…