CVE-2026-22855

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This vulnerability is fixed in 3.20.1.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

History

17 Jun 2026, 10:20

Type Values Removed Values Added
References () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rwp3-g84r-6mx9 - Vendor Advisory, Exploit () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rwp3-g84r-6mx9 - Exploit, Vendor Advisory
Summary
  • (es) FreeRDP es una implementación gratuita del Protocolo de Escritorio Remoto. Antes de la 3.20.1, ocurre una lectura fuera de límites de la pila en la ruta SetAttrib de la tarjeta inteligente cuando cbAttrLen no coincide con la longitud real del búfer NDR. Esta vulnerabilidad está corregida en la 3.20.1.

20 Jan 2026, 18:36

Type Values Removed Values Added
References () https://github.com/FreeRDP/FreeRDP/releases/tag/3.20.1 - () https://github.com/FreeRDP/FreeRDP/releases/tag/3.20.1 - Release Notes
References () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rwp3-g84r-6mx9 - () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rwp3-g84r-6mx9 - Vendor Advisory, Exploit
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1
First Time Freerdp
Freerdp freerdp
CPE cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

14 Jan 2026, 18:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-14 18:16

Updated : 2026-06-17 10:20


NVD link : CVE-2026-22855

Mitre link : CVE-2026-22855

CVE.ORG link : CVE-2026-22855


JSON object : View

Products Affected

freerdp

  • freerdp
CWE
CWE-125

Out-of-bounds Read