Description
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficient length validation for specific capability sets. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed capability data. Due to missing bounds checks, the xrdp process may perform out-of-bounds memory reads, which can result in the termination of the service (Denial of Service). However, since xrdp forks a new process for each connection by default, an out-of-bounds read causing a process crash is unlikely to bring down the entire xrdp service. This issue has been fixed in version 0.10.6.1.
Published: 2026-07-20
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

xrdp is an open source RDP server. The vulnerability arises from improper length validation of capability data in the RDP Confirm Active packet, resulting in an out‑of‑bounds read. This can crash the xrdp process, leading to denial of service for the affected connection but not likely to bring down the entire service.

Affected Systems

The affected product is neutrinolabs xrdp version 0.10.6 and earlier. The fix is available in 0.10.6.1. Systems running earlier releases and accepting native RDP connections are vulnerable.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate impact. EPSS < 1% suggests a very low probability of exploitation. The vulnerability is not listed in CISA KEV. Attackers can send a crafted RDP packet over the standard RDP port without authentication; because the failure only crashes a child process, repeated exploitation could degrade availability but is unlikely to compromise confidentiality or integrity. Overall risk remains moderate, but patching is advisable.

Generated by OpenCVE AI on July 30, 2026 at 18:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade neutrinolabs xrdp to version 0.10.6.1 or later to resolve the out-of-bounds read vulnerability.
  • Restrict the RDP service to trusted networks or enforce firewall rules to block unauthenticated connections and limit exposure.
  • Enable detailed logging and configure automatic restart of xrdp processes to mitigate service disruptions until a patch can be applied.

Generated by OpenCVE AI on July 30, 2026 at 18:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 20 Jul 2026 23:15:00 +0000

Type Values Removed Values Added
First Time appeared Neutrinolabs
Neutrinolabs xrdp
Vendors & Products Neutrinolabs
Neutrinolabs xrdp

Mon, 20 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description xrdp is an open source RDP server. Versions 0.10.6 and prior contain a vulnerability concerning the processing of RDP Confirm Active PDU, where during the capability negotiation phase, the parser did not perform sufficient length validation for specific capability sets. A remote, unauthenticated attacker could potentially exploit this flaw by sending a specially crafted RDP packet containing malformed capability data. Due to missing bounds checks, the xrdp process may perform out-of-bounds memory reads, which can result in the termination of the service (Denial of Service). However, since xrdp forks a new process for each connection by default, an out-of-bounds read causing a process crash is unlikely to bring down the entire xrdp service. This issue has been fixed in version 0.10.6.1.
Title xrdp: Malformed Confirm Active capability sets cause out-of-bounds reads
Weaknesses CWE-126
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}


Subscriptions

Neutrinolabs Xrdp
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-20T19:07:08.673Z

Reserved: 2026-06-16T16:44:00.624Z

Link: CVE-2026-55238

cve-icon Vulnrichment

Updated: 2026-07-20T19:01:35.356Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-30T19:00:09Z

Weaknesses