Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0, a client-side heap buffer overflow occurs in the ClearCodec bands decode path when crafted band coordinates allow writes past the end of the destination surface buffer. A malicious server can trigger a client‑side heap buffer overflow, causing a crash (DoS) and potential heap corruption with code‑execution risk depending on allocator behavior and surrounding heap layout. Version 3.21.0 contains a patch for the issue.
INFO
Published Date :
2026-01-19T17:09:55.715Z
Last Modified :
2026-01-20T14:42:31.717Z
Source :
GitHub_M
AFFECTED PRODUCTS
The following products are affected by CVE-2026-23534 vulnerability.
| Vendors | Products |
|---|---|
| Freerdp |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-23534.