CVE-2026-35512 Details
Description
xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediately update, they should run xrdp as a non-privileged user (default since 0.10.2) to limit the impact of successful exploitation.
A heap-based buffer overflow vulnerability has been identified in xrdp versions prior to 0.10.6. This issue resides in the EGFX (graphics dynamic virtual channel) implementation, where insufficient validation of client-controlled size parameters allows for out-of-bounds writes via crafted PDUs. Exploitation of this vulnerability can lead to process crashes or, in post-authentication scenarios, remote code execution. The vulnerability can be reproduced by sending specially crafted PDUs that exploit the lack of proper size validation, causing an out-of-bounds write that can be manipulated for code execution.
Users should update to xrdp version 0.10.6. If an immediate update is not possible, xrdp can be run as a non-privileged user to limit the impact of exploitation.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6 | [email protected] | PatchRelease Notes |
| https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-jg6p-7fg8-9hh6 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-122 | Heap-based Buffer Overflow | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| neutrinolabs xrdp | < 0.10.6 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 17, 2026 | New CVE Received | [email protected] |