CVE-2026-85090
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.
Schwachstellenklasse
FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.
Betroffene Produkte
- freerdp freerdp
Quellen
- https://github.com/FreeRDP/FreeRDP
- https://github.com/FreeRDP/FreeRDP/blob/3.30.0/libfreerdp/primitives/prim_YUV.c
- https://github.com/FreeRDP/FreeRDP/commit/d0a481cb74ab57bca24791fe11b89464a332d3f1
- https://github.com/FreeRDP/FreeRDP/releases/tag/3.31.0
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-57h7-vw2f-2f9x
- https://www.vulncheck.com/advisories/freerdp-before-3.31.0-heap-out-of-bounds-read-via-avc444
Finden Sie die Schwachstelle, bevor es ein Angreifer tut.
Melden Sie sich mit GitHub an und starten Sie Ihr erstes Audit in weniger als einer Minute. Für den kostenlosen Plan ist keine Kreditkarte nötig.