FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to version 3.21.0,`freerdp_bitmap_decompress_planar` does not validate `nSrcWidth`/`nSrcHeight` against `planar->maxWidth`/`maxHeight` before RLE decode. A malicious server can trigger a clientโside heap buffer overflow, causing a crash (DoS) and potential heap corruption with codeโexecution risk depending on allocator b
VulnCheck: FreeRDP is
Vulnerability
CVE-2026-23530
VulnCheck
Update to v3.21.0