Upstream information

CVE-2026-55648 at MITRE

Description

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.27.0, freerdp_image_copy_from_icon_data in libfreerdp/codec/color.c calculates nWidth multiplied by nHeight multiplied by FreeRDPGetBytesPerPixel(format) in 32-bit arithmetic. A malicious RDP server can send a RAIL TS_ICON_INFO update with dimensions such as 32768 by 32768 and 32 bits per pixel so the required-size calculation wraps, bypassing the cbBitsColor source bounds check before freerdp_image_copy_no_overlap reads attacker-controlled icon data. This affects RemoteApp clients using the vulnerable library path, while xfreerdp has a caller-side mitigation. This issue is fixed in version 3.27.0.

SUSE information

Overall state of this security issue: Does not affect SUSE products

No SUSE Bugzilla entries cross referenced.

No SUSE Security Announcements cross referenced.

List of released packages

Product(s) Fixed package version(s) References
openSUSE Tumbleweed
  • freerdp >= 3.27.1-1.1
  • freerdp-devel >= 3.27.1-1.1
  • freerdp-proxy >= 3.27.1-1.1
  • freerdp-proxy-plugins >= 3.27.1-1.1
  • freerdp-sdl >= 3.27.1-1.1
  • freerdp-server >= 3.27.1-1.1
  • freerdp-wayland >= 3.27.1-1.1
  • libfreerdp-server-proxy3-3 >= 3.27.1-1.1
  • libfreerdp3-3 >= 3.27.1-1.1
  • librdtk0-0 >= 3.27.1-1.1
  • libuwac0-0 >= 3.27.1-1.1
  • libwinpr3-3 >= 3.27.1-1.1
  • rdtk0-devel >= 3.27.1-1.1
  • uwac0-devel >= 3.27.1-1.1
  • winpr-devel >= 3.27.1-1.1
Patchnames:
openSUSE-Tumbleweed-2026-11065


SUSE Timeline for this CVE

CVE page created: Sat Jun 20 11:40:06 2026
CVE page last modified: Thu Aug 20 21:11:48 2026