CVE-2026-85090
PoC massHeap Out-of-Bounds Read in FreeRDP AVC444 Decoding (CVE-2026-85090)
FreeRDP before 3.31.0 contains a heap-based out-of-bounds read (CWE-125) in the general_ChromaV1ToYUV444 function, which runs during chroma plane reconstruction for AVC444 (H.264-based) graphics streams. A malicious or compromised RDP server can send a specially crafted RFX_AVC444_BITMAP_STREAM with specific frame geometry, causing the client to read past the end of the allocated luma plane buffer when decoding the stream. The impact is limited, consistent with the CVSS v4.0 score of 5.3 (Medium) with user interaction required: possible disclosure of adjacent heap memory and/or a crash of the client process, with no evidence of remote code execution. Anyone running a FreeRDP-based RDP client, including distribution packages and applications that link libfreerdp, is affected when a user connects to an attacker-controlled RDP server, since the flaw is triggered by the server's response rather than by the client. No in-the-wild exploitation is known: the issue is not in CISA KEV, EPSS puts the 30-day exploitation probability at 0.3%, and the only public reference is the FreeRDP security advisory GHSA-57h7-vw2f-2f9x.
What to do: Upgrade FreeRDP to 3.31.0 or later, or install your distribution's patched package and restart any applications that link libfreerdp; also check third-party clients, thin clients, and appliances that bundle FreeRDP for vendor updates. Until patched, avoid connecting FreeRDP-based clients to untrusted RDP servers, or disable H.264/AVC444 (advanced graphics) codec negotiation in the client.
| FreeRDP | all versions before 3.31.0 (< 3.31.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.
- Vendors
- freerdp
- Products
- freerdp
- Weakness
- CWE-125
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.