Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-55238
xrdp vulnerability analysis and mitigation

Overview

CVE-2026-55238 is a buffer over-read vulnerability in xrdp, an open-source RDP server, caused by improper input validation during RDP capability negotiation. Versions 0.10.6 and prior are affected; the issue was fixed in version 0.10.6.1. The advisory was published on July 1, 2026, by the xrdp maintainers, with NVD publication on July 20, 2026. It carries a CVSS v3.1 base score of 5.3 (Medium) (GitHub Advisory, Red Hat).

Technical details

The root cause is classified as CWE-126 (Buffer Over-read): during the capability negotiation phase of an RDP session, the xrdp parser fails to perform sufficient length validation on specific capability sets within the RDP Confirm Active PDU. An unauthenticated remote attacker can send a specially crafted RDP packet containing malformed capability data that triggers out-of-bounds memory reads due to missing bounds checks. No authentication or user interaction is required, and the attack can be launched over the network with low complexity. The vulnerability was credited to Thai Son Dinh from VinSOC Labs (R&D) (GitHub Advisory, Red Hat Bugzilla).

Impact

Successful exploitation causes the targeted xrdp connection process to crash, resulting in a Denial of Service for the affected client session. Because xrdp forks a new process for each incoming connection by default, a crash of one forked process does not bring down the entire xrdp service — limiting the availability impact to individual sessions rather than the whole server. There is no confidentiality or integrity impact; data exposure and lateral movement are not associated with this vulnerability (GitHub Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (Feedly). The NVD SSVC assessment confirms exploitation status as "none" and classifies the vulnerability as automatable due to the lack of authentication requirements. The EPSS score is approximately 0.517%, indicating a low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Detection plugins are available from Nessus (plugin 325631) and Qualys (plugin 289094) (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing hosts running xrdp version 0.10.6 or earlier using network scanners (e.g., Shodan, Censys, or Nmap with RDP service detection on TCP port 3389).
  2. Initiate RDP connection: Establish a TCP connection to the target xrdp service on port 3389 (or the configured RDP port) without requiring any credentials.
  3. Craft malformed Confirm Active PDU: Construct a specially crafted RDP Confirm Active PDU containing malformed capability set data with incorrect or oversized length fields that exceed the expected buffer boundaries.
  4. Send malicious packet: Transmit the crafted packet during the RDP capability negotiation phase, before authentication occurs.
  5. Trigger out-of-bounds read: The xrdp parser, lacking proper bounds checks, reads beyond the intended buffer, causing the forked connection process to crash and terminating the RDP session for that client (Denial of Service) (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated RDP connection attempts (TCP port 3389) from a single source IP that terminate abruptly during the capability negotiation phase; malformed RDP PDUs with anomalous capability set lengths detectable via deep packet inspection.
  • Logs: xrdp session logs showing repeated process crashes or abnormal terminations shortly after connection establishment, before authentication; entries such as xrdp_process_main_loop: exit or segmentation fault messages in /var/log/xrdp.log or syslog.
  • Process: Unexpected termination of xrdp child processes (forked per connection) visible via system monitoring tools; elevated rate of short-lived xrdp process spawning and dying in rapid succession (GitHub Advisory).

Mitigation and workarounds

Upgrade xrdp to version 0.10.6.1 or later, which was released on July 6, 2026, and addresses this vulnerability along with nine other CVEs (xrdp Release). If immediate patching is not feasible, restrict network access to the RDP service (TCP port 3389) using firewall rules to limit exposure to trusted networks or VPN-connected clients only. Fedora package updates incorporating the fix have also been published (Red Hat Bugzilla).

Community reactions

The vulnerability was reported by Thai Son Dinh from VinSOC Labs (R&D) and credited in the official GitHub Security Advisory. The xrdp maintainer (metalefty) published the advisory and the patched release. Coverage has appeared in Linux security news outlets including LinuxSecurity.com and pro-linux.de, and the vulnerability has been indexed by Tenable Nessus and Qualys scanners. No significant social media controversy or notable researcher commentary beyond standard disclosure has been observed (GitHub Advisory).

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

xrdp: 0.9.21.1-1+deb12u3

Fixed

sid

xrdp: 0.10.6.1-2

Fixed

trixie

xrdp: 0.10.1-3.1+deb13u2

Fixed

Ubuntu

Unknown

bionic (esm-apps)

xrdp

Unknown

devel

xrdp

Unknown

focal (esm-apps)

xrdp

Unknown

jammy

xrdp

Unknown

jammy (esm-apps)

xrdp

Unknown

noble

xrdp

Unknown

noble (esm-apps)

xrdp

Unknown

resolute

xrdp

Unknown

SourceThis report was generated using AI

Related xrdp vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-54538HIGH7.5
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026
CVE-2026-55626HIGH7.3
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026
CVE-2026-55645MEDIUM6.5
  • xrdp logoxrdp
  • xrdp-debuginfo
NoYesJul 20, 2026
CVE-2026-55639MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-devel
NoYesJul 20, 2026
CVE-2026-55238MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-debuginfo
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management