---
id: CVE-2026-55194
title: FreeRDP is a free implementation of the Remote Desktop Protocol
summary: >-
  FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to
  3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c
  ensures the response reassembly stream capacity using only the server-declared
  alloc_hint …
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-122
  - CWE-120
vendor: freerdp
product: freerdp
affected:
  - freerdp < 3.27.0
patched:
  - freerdp 3.27.0
published: '2026-08-19'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T15:15:35.073'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55194'
references:
  - url: >-
      https://github.com/FreeRDP/FreeRDP/commit/9f2da52c2341cc14a96ad12e69c5b83d0bcd8b5a
    label: security-advisories@github.com
  - url: 'https://github.com/FreeRDP/FreeRDP/pull/12873'
    label: security-advisories@github.com
  - url: 'https://github.com/FreeRDP/FreeRDP/releases/tag/3.27.0'
    label: security-advisories@github.com
  - url: 'https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9gxm-3mf5-f5cx'
    label: security-advisories@github.com
  - url: >-
      https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-55194.json
  - url: 'https://access.redhat.com/security/cve/CVE-2026-55194'
  - url: 'https://bugzilla.redhat.com/show_bug.cgi?id=2519824'
  - url: 'https://www.cve.org/CVERecord?id=CVE-2026-55194'
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-55194'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68707'
  - url: 'https://access.redhat.com/errata/RHSA-2026:68706'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61378'
  - url: 'https://access.redhat.com/errata/RHSA-2026:62571'
  - url: 'https://access.redhat.com/errata/RHSA-2026:65855'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66281'
  - url: 'https://access.redhat.com/errata/RHSA-2026:66282'
  - url: 'https://access.redhat.com/errata/RHSA-2026:61379'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71390'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71388'
  - url: 'https://access.redhat.com/errata/RHSA-2026:71387'
tags:
  - nvd
  - cve.org
  - exploit-available
  - csaf
  - vex
  - red-hat
epss: 0.00619
epssPercentile: 0.47444
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-08-21T03:55:49.884406Z'
scores:
  nvd: 9.8
  cna: 8.7
  vendor: 8.8
ingestedAt: '2026-09-13T18:54:55.030Z'
---

## Overview

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, rpc_client_recv_fragment in libfreerdp/core/gateway/rpc_client.c ensures the response reassembly stream capacity using only the server-declared alloc_hint rather than the actual StubLength about to be written. A malicious TS Gateway can send a PTYPE_RESPONSE with a small alloc_hint and a much larger frag_length, causing Stream_Write to copy attacker-controlled stub data beyond the 4096-byte pdu->s buffer. This can crash the client and may permit code execution through heap corruption. This issue is fixed in version 3.27.0.

## Affected

- `freerdp < 3.27.0`

## Remediation

Upgrade past the affected range:

- `freerdp 3.27.0`

## Vendor advisories

- **RHSA-2026:68707** · Red Hat · fixed in: Red Hat Enterprise Linux Server (v. 7 ELS), Red Hat Enterprise Linux Server Optional (v. 7 ELS) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68707)
- **RHSA-2026:68706** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v. 10.0), Red Hat Enterprise Linux CodeReady Linux Builder EUS (v. 10.0) · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68706)
- **RHSA-2026:61378** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 10), Red Hat Enterprise Linux CodeReady Linux Builder (v. 10) · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61378)
- **RHSA-2026:62571** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 8), Red Hat Enterprise Linux CRB (v. 8) · released 2026-09-02 · [advisory](https://access.redhat.com/errata/RHSA-2026:62571)
- **RHSA-2026:65855** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.4), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.4) · released 2026-09-09 · [advisory](https://access.redhat.com/errata/RHSA-2026:65855)
- **RHSA-2026:66281** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream AUS (v.8.6), Red Hat Enterprise Linux AppStream EUS EXTENSION (v.8.6) · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66281)
- **RHSA-2026:66282** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.8.8), Red Hat Enterprise Linux AppStream TUS (v.8.8) · released 2026-09-10 · [advisory](https://access.redhat.com/errata/RHSA-2026:66282)
- **RHSA-2026:61379** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream (v. 9), Red Hat Enterprise Linux CodeReady Linux Builder (v. 9) · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61379)
- **RHSA-2026:71390** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.4) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71390)
- **RHSA-2026:71388** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream E4S (v.9.2) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71388)
- **RHSA-2026:71387** · Red Hat · fixed in: Red Hat Enterprise Linux AppStream EUS (v.9.6), Red Hat CodeReady Linux Builder EUS (v.9.6) · released 2026-09-24 · [advisory](https://access.redhat.com/errata/RHSA-2026:71387)
