CVE-2026-40033

FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps coordinates to UINT16_MAX but performs copy operations using unclamped cache entry dimensions, enabling malicious RDP servers to trigger large out-of-bounds writes and potentially achieve remote code execution or client crash.
Configurations

Configuration 1 (hide)

cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*

History

27 Jul 2026, 13:17

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:46393 -

24 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) FreeRDP anterior a la versión 3.26.0 contiene una vulnerabilidad de desbordamiento de búfer de pila en gdi_CacheToSurface que permite a atacantes remotos escribir memoria de pila fuera de los límites. La vulnerabilidad ocurre porque la validación de rectángulos limita las coordenadas a UINT16_MAX pero realiza operaciones de copia utilizando dimensiones de entrada de caché no limitadas, lo que permite a servidores RDP maliciosos desencadenar escrituras grandes fuera de los límites y potencialmente lograr ejecución remota de código o un fallo del cliente.

08 Jul 2026, 13:16

Type Values Removed Values Added
References
  • () https://access.redhat.com/errata/RHSA-2026:36203 -

30 Jun 2026, 03:19

Type Values Removed Values Added
CWE CWE-787
References
  • () https://access.redhat.com/security/cve/CVE-2026-40033 -
  • () https://bugzilla.redhat.com/show_bug.cgi?id=2481473 -
  • () https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-40033.json -

17 Jun 2026, 10:44

Type Values Removed Values Added
References
  • {'url': 'https://github.com/FreeRDP/FreeRDP/commit/23b36cd00ebf0ccd97750fcdbc9aa2f362352da7', 'tags': ['Patch'], 'source': 'disclosure@vulncheck.com'}
  • () https://github.com/FreeRDP/FreeRDP/commit/d7508ebcd82842a691ae4941e5104d14240a89ae -
  • () https://github.com/FreeRDP/FreeRDP/pull/12713 -

27 May 2026, 14:48

Type Values Removed Values Added
CPE cpe:2.3:a:freerdp:freerdp:*:*:*:*:*:*:*:*
References () https://github.com/FreeRDP/FreeRDP/commit/23b36cd00ebf0ccd97750fcdbc9aa2f362352da7 - () https://github.com/FreeRDP/FreeRDP/commit/23b36cd00ebf0ccd97750fcdbc9aa2f362352da7 - Patch
References () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p6r2-4hgm-m6ff - () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p6r2-4hgm-m6ff - Exploit, Mitigation, Vendor Advisory
References () https://www.vulncheck.com/advisories/freerdp-heap-buffer-overflow-in-gdi-cachetosurface-via-rectangle-validation-bypass - () https://www.vulncheck.com/advisories/freerdp-heap-buffer-overflow-in-gdi-cachetosurface-via-rectangle-validation-bypass - Third Party Advisory
First Time Freerdp freerdp
Freerdp

26 May 2026, 16:16

Type Values Removed Values Added
References () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p6r2-4hgm-m6ff - () https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-p6r2-4hgm-m6ff -

26 May 2026, 15:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-26 15:16

Updated : 2026-07-27 13:17


NVD link : CVE-2026-40033

Mitre link : CVE-2026-40033

CVE.ORG link : CVE-2026-40033


JSON object : View

Products Affected

freerdp

  • freerdp
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write