CVE-2026-41521
描述
xrdp is an open source RDP server. Versions 0.10.6 and prior contain an integer overflow vulnerability when processing screen update messages within the vnc-any connection mode. A malicious remote VNC server can send crafted image dimensions that cause an integer overflow during memory buffer size calculation, resulting in an undersized allocation. Subsequent processing of the incoming image data using the original oversized parameters leads to an out-of-bounds read. An unauthenticated remote attacker could exploit this flaw to disclose sensitive information from the heap memory or cause a denial of service (DoS) via a process crash. This issue has been fixed in version 0.10.6.1.
如何修補 CVE-2026-41521
目前尚未發布修補版本。可考慮移除受影響套件,或參考下方連結中的上游建議。
- Debian/xrdp—未列出修補版本
CVE-2026-41521 正在被利用嗎?
目前沒有被利用訊號。CVE-2026-41521 既不在 CISA KEV 也沒有最新的 EPSS 分數。
受影響套件(1)
- from 0