Description
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing a malicious RDP server to send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the input buffer. This issue is fixed in version 3.28.0.
Published: 2026-07-10
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

FreeRDP clients between versions 3.21.0 and 3.27.x that enable the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing a malicious RDP server to send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the input buffer. This out-of-bounds read can expose a byte of heap memory to an attacker, thereby providing a potential source of information disclosure.

Affected Systems

Any FreeRDP client built from release 3.21.0 up to, but not including, version 3.28.0 that has the GFX pipeline enabled is affected. The vulnerability is resolved in FreeRDP 3.28.0 and later. No other vendors or product families are implicated.

Risk and Exploitability

The CVSS score of 5.1 denotes moderate severity, while the EPSS score of less than 1% reflects a low chance of exploitation in the wild. The vulnerability is not listed in CISA's KEV catalog. An attacker simply needs to act as an RDP server that dispatches a malformed, truncated planar payload to a running, vulnerable client; no elevated privileges are necessary. Consequently, exploitation is remote, limited to clients that accept untrusted server data, and its likelihood remains modest unless a targeted threat actor seeks to leverage the information disclosure.

Generated by OpenCVE AI on July 28, 2026 at 08:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade all affected FreeRDP clients to version 3.28.0 or newer to fully eliminate the out-of-bounds read as part of the complete fix for CVE-2026-23530.
  • If an immediate upgrade is not feasible, restrict inbound RDP connections to trusted networks or hosts so that the vulnerable client only accepts connections from known, trusted servers.
  • Alternatively, disable the GFX pipeline for the client, accepting reduced graphical performance as a temporary trade-off.

Generated by OpenCVE AI on July 28, 2026 at 08:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sat, 11 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L'}

threat_severity

Moderate


Fri, 10 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
First Time appeared Freerdp
Freerdp freerdp
Vendors & Products Freerdp
Freerdp freerdp

Fri, 10 Jul 2026 20:00:00 +0000

Type Values Removed Values Added
Description FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing a malicious RDP server to send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the input buffer. This issue is fixed in version 3.28.0.
Title FreeRDP planar_decompress_plane_rle_only: heap OOB read — incomplete fix for CVE-2026-23530
Weaknesses CWE-125
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-14T13:54:51.055Z

Reserved: 2026-06-24T01:45:48.698Z

Link: CVE-2026-57158

cve-icon Vulnrichment

Updated: 2026-07-14T13:54:19.386Z

cve-icon NVD

No data.

cve-icon Redhat

Severity : Moderate

Publid Date: 2026-07-10T19:49:03Z

Links: CVE-2026-57158 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T08:15:06Z

Weaknesses