FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1.
Metrics
Affected Vendors & Products
References
History
Wed, 14 Jan 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 14 Jan 2026 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, RDPEAR’s NDR array reader does not perform bounds checking on the on‑wire element count and can write past the heap buffer allocated from hints, causing a heap buffer overflow in ndr_read_uint8Array. This vulnerability is fixed in 3.20.1. | |
| Title | FreeRDP has a heap-buffer-overflow in ndr_read_uint8Array | |
| Weaknesses | CWE-787 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-01-14T21:04:53.435Z
Reserved: 2026-01-12T16:20:16.745Z
Link: CVE-2026-22853
Updated: 2026-01-14T21:04:50.720Z
Status : Received
Published: 2026-01-14T18:16:42.790
Modified: 2026-01-14T18:16:42.790
Link: CVE-2026-22853
No data.
OpenCVE Enrichment
No data.