CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2026-22859

Critical · CVSS 9.1

FreeRDP — Out-of-bounds read via unchecked server-supplied array index (CWE-125, CWE-129)

CVSS
9.1
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-125, CWE-129, CWE-125

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, the URBDRC client does not perform bounds checking on server‑supplied MSUSB_INTERFACE_DESCRIPTOR values and uses them as indices in libusb_udev_complete_msconfig_setup, causing an out‑of‑bounds read. This vulnerability is fixed in 3.20.1.

Search profile — drives PoC discovery

Symbols URBDRCMSUSB_INTERFACE_DESCRIPTORlibusb_udev_complete_msconfig_setupurbdrc_clientGHSA-56f5-76qv-2r36
Keywords CVE-2026-22859FreeRDPURBDRCMSUSB_INTERFACE_DESCRIPTORout-of-bounds readlibusb_udev_complete_msconfig_setupbounds checkingFreeRDP 3.20.1GHSA-56f5-76qv-2r36
Versions: < 3.20.1

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-06-30T06:00:22.000Z · profiled 2026-06-30T18:30:14.000Z