CVE-2026-22855: NixOS vulnerability analysis and mitigation
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.20.1, a heap out-of-bounds read occurs in the smartcard SetAttrib path when cbAttrLen does not match the actual NDR buffer length. This vulnerability is fixed in 3.20.1.
Source: NVD
Related NixOS vulnerabilities:
CVE ID
Severity
Score
Technologies
Component name
CISA KEV exploit
Has fix
Published date
CVE-2026-21010
HIGH
7.8
NixOS
android
No
No
Apr 13, 2026
CVE-2026-21012
MEDIUM
6.8
NixOS
android
No
No
Apr 13, 2026
CVE-2026-21011
MEDIUM
5.4
NixOS
android
No
No
Apr 13, 2026
CVE-2026-21008
MEDIUM
5.1
NixOS
android
No
No
Apr 13, 2026
CVE-2026-21009
MEDIUM
4.1
NixOS
android
No
No
Apr 13, 2026
Free Vulnerability Assessment
Benchmark your Cloud Security Posture
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.