
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55238 is an improper input validation vulnerability in xrdp's RDP capability negotiation phase that can lead to Denial of Service. It affects xrdp versions through 0.10.6, with the patched version being 0.10.6.1. The vulnerability was published on July 1, 2026, by the xrdp maintainers. It carries a CVSS v3.1 base score of 5.3 (Moderate) (xrdp Advisory).
The root cause is a buffer over-read (CWE-126) in xrdp's processing of RDP Confirm Active PDUs during capability negotiation. The parser fails to perform sufficient length validation for specific capability sets, allowing a remote, unauthenticated attacker to send a specially crafted RDP packet with malformed capability data. Due to missing bounds checks, the xrdp process may perform out-of-bounds memory reads, leading to process termination. Because xrdp forks a new process per connection by default, a crash of the child process is unlikely to bring down the entire xrdp service (xrdp Advisory).
Successful exploitation results in a Denial of Service limited to the individual xrdp child process handling the malicious connection, with no impact on confidentiality or integrity. Because xrdp spawns a separate process per connection, the overall xrdp service is unlikely to be fully disrupted, though repeated attacks could degrade availability for legitimate users. There is no evidence of code execution, privilege escalation, or data exposure risk associated with this vulnerability (xrdp Advisory).
/var/log/xrdp.log or syslog) showing abnormal termination; segmentation fault or signal 11 messages associated with xrdp worker processes.ps or process accounting logs.The vendor has released xrdp version 0.10.6.1 as the patched release, which addresses the insufficient length validation in capability set parsing. Administrators should upgrade to xrdp 0.10.6.1 or later as the primary remediation. As a temporary workaround, restricting access to the xrdp port (default 3389/TCP) via firewall rules to trusted IP ranges can reduce exposure. Fedora users can apply the updated packages available through Fedora security advisories (xrdp Advisory, Fedora Advisory).
The vulnerability was reported by researchers sondt99 and TristanInSec and published via the xrdp GitHub Security Advisory on July 1, 2026. Fedora security updates incorporating the fix were noted in community Linux security news outlets shortly after disclosure (Fedora Advisory, Pro-Linux). Tenable released Nessus detection plugins promptly following the advisory, indicating standard industry response to a moderate-severity issue.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."