FreeRDP is a free implementation of the Remote Desktop Protocol. From 3.21.0 before 3.28.0, FreeRDP clients using the GFX pipeline contain an incomplete fix for CVE-2026-23530 in planar_decompress_plane_rle_only in libfreerdp/codec/planar.c, allowing a malicious RDP server to send a truncated RDPGFX_CMDID_WIRETOSURFACE_1 planar payload that reads one byte past the input buffer. This issue is fixed in version 3.28.0.
1.1.0~git20140921.1.440916e+dfsg1-5ubuntu11.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.21.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.31.1.0~git20140921.1.440916e+dfsg1-5ubuntu1.41.1.0~git20140921.1.440916e+dfsg1-15ubuntu11.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.04.11.1.0~git20140921.1.440916e+dfsg1-15ubuntu1.18.04.23.30.0+dfsg-0ubuntu0.24.04.13.14.0+dfsg-1ubuntu13.15.0+dfsg-2.13.16.0+dfsg-1ubuntu13.16.0+dfsg-23.16.0+dfsg-2ubuntu0.13.16.0+dfsg-2ubuntu0.33.16.0+dfsg-2ubuntu0.43.16.0+dfsg-2ubuntu0.53.30.0+dfsg-0ubuntu0.26.04.1Exploitability
AV:NAC:LAT:NPR:NUI:AVulnerable System
VC:LVI:NVA:LSubsequent System
SC:NSI:NSA:NCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:L/SC:N/SI:N/SA:N