
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55238 is a buffer over-read vulnerability in xrdp, an open-source RDP server, caused by improper input validation during RDP capability negotiation. Versions 0.10.6 and prior are affected; the issue was fixed in version 0.10.6.1. The advisory was published on July 1, 2026, by the xrdp maintainers, with NVD publication on July 20, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Red Hat).
The root cause is classified as CWE-126 (Buffer Over-read): during the capability negotiation phase of an RDP session, the xrdp parser fails to perform sufficient length validation on specific capability sets within the RDP Confirm Active PDU. An unauthenticated remote attacker can send a specially crafted RDP packet containing malformed capability data that triggers out-of-bounds memory reads due to missing bounds checks. No authentication or user interaction is required, and the attack can be launched over the network with low complexity. The vulnerability was credited to Thai Son Dinh from VinSOC Labs (R&D) (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation causes the targeted xrdp connection process to crash, resulting in a Denial of Service for the affected client session. Because xrdp forks a new process for each incoming connection by default, a crash of one forked process does not bring down the entire xrdp service — limiting the availability impact to individual sessions rather than the whole server. There is no confidentiality or integrity impact; data exposure and lateral movement are not associated with this vulnerability (GitHub Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (Feedly). The NVD SSVC assessment confirms exploitation status as "none" and classifies the vulnerability as automatable due to the lack of authentication requirements. The EPSS score is approximately 0.517%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Detection plugins are available from Nessus (plugin 325631) and Qualys (plugin 289094) (Feedly).
xrdp_process_main_loop: exit or segmentation fault messages in /var/log/xrdp.log or syslog.Upgrade xrdp to version 0.10.6.1 or later, which was released on July 6, 2026, and addresses this vulnerability along with nine other CVEs (xrdp Release). If immediate patching is not feasible, restrict network access to the RDP service (TCP port 3389) using firewall rules to limit exposure to trusted networks or VPN-connected clients only. Fedora package updates incorporating the fix have also been published (Red Hat Bugzilla).
The vulnerability was reported by Thai Son Dinh from VinSOC Labs (R&D) and credited in the official GitHub Security Advisory. The xrdp maintainer (metalefty) published the advisory and the patched release. Coverage has appeared in Linux security news outlets including LinuxSecurity.com and pro-linux.de, and the vulnerability has been indexed by Tenable Nessus and Qualys scanners. No significant social media controversy or notable researcher commentary beyond standard disclosure has been observed (GitHub Advisory).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."