xrdp: lib_palette_update Heap Buffer Overflow & RCE
Published Jul 20, 2026
9.8
CRITICALCVSS 3.1
EPSS 1.11%
Description
xrdp is an open source RDP server. Versions 0.10.6 and prior contain a missing bounds check in xrdp, which allows a heap-based buffer overflow when operating in vnc-any mode. The issue occurs during the handling of RFB protocol color map messages from a VNC server, where incoming color indices are not properly validated. A malicious VNC server can exploit this flaw by sending crafted messages with out-of-range values, leading to an out-of-bounds write on the heap. This memory corruption can result in a denial of service (DoS) or potentially allow remote code execution (RCE) prior to authentication. This issue has been fixed in version 0.10.6.1.
Affected products
-
- Version < 0.10.6.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Neutrinolabs | Xrdp | n/a |
|
- < 0.10.6.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46017 Advisory
- https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1 x_refsource_MISCRelease Notes
- https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-w5vg-6qmv-j63j x_refsource_CONFIRMMitigationVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-46017 | Advisory | |
| https://github.com/neutrinolabs/xrdp/releases/tag/v0.10.6.1 | x_refsource_MISCRelease Notes | |
| https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-w5vg-6qmv-j63j | x_refsource_CONFIRMMitigationVendor Advisory |
Change history (0)
No recorded changes yet.