Fiche vulnérabilité
CVE-2026-22858 : faille critique freerdp freerdp (CVSS 9.1)
Description
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, global-buffer-overflow was observed in FreeRDP's Base64 decoding path. The root cause appears to be implementation-defined char signedness: on Arm/AArch64 builds, plain char is treated as unsigned, so the guard c <= 0 can be optimized into a simple c != 0 check. As a result, non-ASCII bytes (e.g., 0x80-0xFF) may bypass the intended range restriction and be used as an index into a global lookup table, causing out-of-bounds access. This vulnerability is fixed in 3.20.1.
En bref
- Sévérité
- Critique (CVSS 9.1)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 14 janv. 2026
- Dernière mise à jour
- 15 juil. 2026
Produits concernés
- freerdp freerdp
Références
- Fiche CVE-2026-22858 sur le NVD (NIST)
- github.com/FreeRDP/FreeRDP/releases/tag/3.20.1
- github.com/FreeRDP/FreeRDP/security/advisories/GHSA…
- access.redhat.com/errata/RHSA-2026:19033
- access.redhat.com/errata/RHSA-2026:3067
- access.redhat.com/errata/RHSA-2026:3068
- access.redhat.com/errata/RHSA-2026:3334
- access.redhat.com/errata/RHSA-2026:3975
- access.redhat.com/errata/RHSA-2026:4121
- access.redhat.com/errata/RHSA-2026:4433
- access.redhat.com/errata/RHSA-2026:4437
- access.redhat.com/errata/RHSA-2026:4438
- access.redhat.com/errata/RHSA-2026:4439
- access.redhat.com/errata/RHSA-2026:4440
- access.redhat.com/errata/RHSA-2026:4446
- access.redhat.com/errata/RHSA-2026:4471