Impact
FreeRDP clients between versions 3.21.0 and 3.27.x that enable the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing a malicious RDP server to send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the input buffer. This out-of-bounds read can expose a byte of heap memory to an attacker, thereby providing a potential source of information disclosure.
Affected Systems
Any FreeRDP client built from release 3.21.0 up to, but not including, version 3.28.0 that has the GFX pipeline enabled is affected. The vulnerability is resolved in FreeRDP 3.28.0 and later. No other vendors or product families are implicated.
Risk and Exploitability
The CVSS score of 5.1 denotes moderate severity, while the EPSS score of less than 1% reflects a low chance of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. An attacker simply needs to act as an RDP server that dispatches a malformed, truncated planar payload to a running, vulnerable client; no elevated privileges are necessary. Consequently, exploitation is remote, limited to clients that accept untrusted server data, and its likelihood remains modest unless a targeted threat actor seeks to leverage the information disclosure.
OpenCVE Enrichment