CVE-2026-22853
Critical · CVSS 9.8FreeRDP — Heap buffer overflow in NDR array parsing (CWE-787 out-of-bounds write)
- CVSS
- 9.8
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-787, CWE-787
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.
Search profile — drives PoC discovery
Symbols ndr_read_uint8ArrayRDPEARNDR array readerndr_readrdpearelement countheap buffer overflow
Keywords CVE-2026-22853FreeRDPheap buffer overflowndr_read_uint8ArrayRDPEARNDR arraybounds checkingGHSA-47v9-p4gp-w5chFreeRDP 3.20.1RDP heap overflow PoC
Versions: < 3.20.1
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 0
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
- https://github.com/FreeRDP/FreeRDP/releases/tag/3.20.1
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-47v9-p4gp-w5ch
- https://access.redhat.com/errata/RHSA-2026:19033
- https://access.redhat.com/errata/RHSA-2026:3068
- https://access.redhat.com/errata/RHSA-2026:4121
- https://access.redhat.com/security/cve/CVE-2026-22853
- https://bugzilla.redhat.com/show_bug.cgi?id=2429647
- https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-22853.json
Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z