ZeroHour

CVE-2026-85090

PoC mass

Heap Out-of-Bounds Read in FreeRDP AVC444 Decoding (CVE-2026-85090)

CVSS 4.0
5.3 medium
EPSS
<1%p24
Published
()
Modified
AI analysis

FreeRDP before 3.31.0 contains a heap-based out-of-bounds read (CWE-125) in the general_ChromaV1ToYUV444 function, which runs during chroma plane reconstruction for AVC444 (H.264-based) graphics streams. A malicious or compromised RDP server can send a specially crafted RFX_AVC444_BITMAP_STREAM with specific frame geometry, causing the client to read past the end of the allocated luma plane buffer when decoding the stream. The impact is limited, consistent with the CVSS v4.0 score of 5.3 (Medium) with user interaction required: possible disclosure of adjacent heap memory and/or a crash of the client process, with no evidence of remote code execution. Anyone running a FreeRDP-based RDP client, including distribution packages and applications that link libfreerdp, is affected when a user connects to an attacker-controlled RDP server, since the flaw is triggered by the server's response rather than by the client. No in-the-wild exploitation is known: the issue is not in CISA KEV, EPSS puts the 30-day exploitation probability at 0.3%, and the only public reference is the FreeRDP security advisory GHSA-57h7-vw2f-2f9x.

What to do: Upgrade FreeRDP to 3.31.0 or later, or install your distribution's patched package and restart any applications that link libfreerdp; also check third-party clients, thin clients, and appliances that bundle FreeRDP for vendor updates. Until patched, avoid connecting FreeRDP-based clients to untrusted RDP servers, or disable H.264/AVC444 (advanced graphics) codec negotiation in the client.

Affected
FreeRDPall versions before 3.31.0 (< 3.31.0)
Estimated exposure
mass≈ millions of installed instances (FreeRDP ships as a packaged RDP client/library across all major Linux distributions and is embedded in many thin-client and… — Estimated from deployment patterns: FreeRDP is the de facto open-source RDP client library packaged in major Linux/BSD distributions and bundled in numerous third-party clients, thin clients, and appliances, implying an installed base…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.

Vendors
freerdp
Products
freerdp
Weakness
CWE-125
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.