CVE-2026-57158
Critical · CVSS 9.1FreeRDP — Out-of-bounds read (OOB read) in GFX pipeline planar RLE decompression
- CVSS
- 9.1
- nvd
- EPSS
- 0.69%
- 49th pct
- KEV
- No
- Class
- oss containerizable
- CWE-125
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing a malicious RDP server to send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the input buffer. This issue is fixed in version 3.28.0.
Search profile — drives PoC discovery
Symbols planar_decompress_plane_rle_onlylibfreerdp/codec/planar.cRDPGFX_CMDID_WIRETOSURFACE_1planar_decompressrdpgfxgfx_pipeline
Keywords CVE-2026-57158FreeRDPplanar_decompress_plane_rle_onlyRDPGFX_CMDID_WIRETOSURFACE_1GFX pipeline OOB readFreeRDP 3.21.0FreeRDP 3.28.0CVE-2026-23530 incomplete fixplanar.c out-of-boundsRDP malicious server OOBGHSA-mp3f-59pg-c5pp
Versions: 3.21.0 to < 3.28.0
References
- https://github.com/FreeRDP/FreeRDP/commit/a7e797626fcb7f1d556ce63febb84f9f4a822731
- https://github.com/FreeRDP/FreeRDP/pull/12952
- https://github.com/FreeRDP/FreeRDP/releases/tag/3.28.0
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mp3f-59pg-c5pp
- https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mp3f-59pg-c5pp
Status: enriched · ingested 2026-07-14T00:00:21.000Z · profiled 2026-07-14T00:30:21.000Z