CVE-2026-55238
xrdp vulnerability analysis and mitigation

Overview

CVE-2026-55238 is an improper input validation vulnerability in xrdp's RDP capability negotiation phase that can lead to Denial of Service. It affects xrdp versions through 0.10.6, with the patched version being 0.10.6.1. The vulnerability was published on July 1, 2026, by the xrdp maintainers. It carries a CVSS v3.1 base score of 5.3 (Moderate) (xrdp Advisory).

Technical details

The root cause is a buffer over-read (CWE-126) in xrdp's processing of RDP Confirm Active PDUs during capability negotiation. The parser fails to perform sufficient length validation for specific capability sets, allowing a remote, unauthenticated attacker to send a specially crafted RDP packet with malformed capability data. Due to missing bounds checks, the xrdp process may perform out-of-bounds memory reads, leading to process termination. Because xrdp forks a new process per connection by default, a crash of the child process is unlikely to bring down the entire xrdp service (xrdp Advisory).

Impact

Successful exploitation results in a Denial of Service limited to the individual xrdp child process handling the malicious connection, with no impact on confidentiality or integrity. Because xrdp spawns a separate process per connection, the overall xrdp service is unlikely to be fully disrupted, though repeated attacks could degrade availability for legitimate users. There is no evidence of code execution, privilege escalation, or data exposure risk associated with this vulnerability (xrdp Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing hosts running xrdp (default port 3389/TCP) using tools like Shodan or Nmap, targeting versions ≤ 0.10.6.
  2. Craft malicious RDP packet: Construct a specially crafted RDP Confirm Active PDU containing malformed capability set data with invalid or oversized length fields.
  3. Send packet to target: Transmit the crafted packet to the xrdp service without requiring authentication, targeting the capability negotiation phase of the RDP handshake.
  4. Trigger out-of-bounds read: The xrdp parser reads beyond the intended buffer boundary due to missing bounds checks, causing the child process to crash and terminating the session (Denial of Service) (xrdp Advisory).

Indicators of compromise

  • Network: Unexpected or malformed RDP connection attempts on port 3389/TCP from unknown sources; connections that terminate abruptly during the capability negotiation phase.
  • Logs: Repeated xrdp child process crash entries in system logs (e.g., /var/log/xrdp.log or syslog) showing abnormal termination; segmentation fault or signal 11 messages associated with xrdp worker processes.
  • Process: Frequent short-lived xrdp child process spawns and exits without completing a full RDP session, potentially visible via ps or process accounting logs.

Mitigation and workarounds

The vendor has released xrdp version 0.10.6.1 as the patched release, which addresses the insufficient length validation in capability set parsing. Administrators should upgrade to xrdp 0.10.6.1 or later as the primary remediation. As a temporary workaround, restricting access to the xrdp port (default 3389/TCP) via firewall rules to trusted IP ranges can reduce exposure. Fedora users can apply the updated packages available through Fedora security advisories (xrdp Advisory, Fedora Advisory).

Community reactions

The vulnerability was reported by researchers sondt99 and TristanInSec and published via the xrdp GitHub Security Advisory on July 1, 2026. Fedora security updates incorporating the fix were noted in community Linux security news outlets shortly after disclosure (Fedora Advisory, Pro-Linux). Tenable released Nessus detection plugins promptly following the advisory, indicating standard industry response to a moderate-severity issue.

Additional resources


SourceThis report was generated using AI

Related xrdp vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55626HIGH8
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026
CVE-2026-54538HIGH7.5
  • xrdp logoxrdp
  • cpe:2.3:a:neutrinolabs:xrdp
NoYesJul 20, 2026
CVE-2026-55645MEDIUM6.5
  • xrdp logoxrdp
  • xrdp-debugsource
NoYesJul 20, 2026
CVE-2026-55639MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-debuginfo
NoYesJul 20, 2026
CVE-2026-55238MEDIUM5.3
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management