
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55645 is an out-of-bounds read vulnerability in xrdp, an open-source RDP server, affecting versions 0.10.6 and prior. The flaw exists in the processing of Client Control PDUs during the RDP connection sequence, where the parser fails to perform sufficient length validation before reading data fields from the network stream. It was published on July 20, 2026, and fixed in version 0.10.6.1 released July 6, 2026. The vulnerability carries a CVSS v3.1 base score of 6.5 (Medium) (GitHub Advisory, Red Hat).
The root cause is classified as CWE-125 (Out-of-bounds Read): the xrdp Client Control PDU parser does not validate the length of incoming data fields before reading them from the network stream, allowing reads beyond the intended buffer boundary. An unauthenticated remote attacker can exploit this by sending a specially crafted, truncated Client Control PDU over the network (TCP port 3389 by default) with no privileges or user interaction required. Because xrdp forks a new child process for each incoming connection, the out-of-bounds read occurs within the forked process rather than the main daemon. The attack is automatable and maps to CAPEC-540 (Overread Buffers) (GitHub Advisory, Red Hat Bugzilla).
Successful exploitation can cause the xrdp child process handling the connection to crash, resulting in a Denial of Service for that session, and may also leak sensitive memory contents (low confidentiality impact) due to the out-of-bounds read. Because xrdp forks a new process per connection, a crash is unlikely to terminate the entire xrdp service, limiting the availability impact to individual sessions rather than a full service outage. There is no integrity impact, and lateral movement potential is low given the constrained scope of the vulnerability (GitHub Advisory, Red Hat).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of publication (GitHub Advisory). The vulnerability is automatable (no user interaction or privileges required), but the EPSS score is low at approximately 0.0048, indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported. Detection plugins are available via Nessus (plugin 325637) and Qualys (plugin 289094) (Feedly).
/var/log/xrdp.log or /var/log/xrdp-sesman.log.xrdp or xrdp-sesman) visible in process monitoring tools; core dump files generated in the xrdp working directory following crashes.The primary remediation is to upgrade xrdp to version 0.10.6.1 or later, which was released on July 6, 2026, and addresses CVE-2026-55645 along with nine other CVEs (xrdp Release). As a temporary workaround where immediate patching is not feasible, restrict network access to the RDP service (TCP port 3389) to trusted IP ranges using firewall rules or network segmentation. Fedora packages incorporating the fix have been published and are available through standard distribution update channels (Red Hat).
The vulnerability was reported by researcher TristanInSec and disclosed via GitHub Security Advisories by xrdp maintainer metalefty on July 2, 2026 (GitHub Advisory). Red Hat tracked the issue via Bugzilla and rated it medium severity, consistent with the upstream CVSS score (Red Hat Bugzilla). Coverage appeared in Linux security news outlets including LinuxSecurity and Pro-Linux following the Fedora package updates, but broader community reaction has been limited given the moderate severity and absence of active exploitation.
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."