
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-55645 is an out-of-bounds read vulnerability in xrdp's Client Control PDU processing that allows a remote, unauthenticated attacker to cause a Denial of Service or potentially read limited memory contents. It affects xrdp versions through 0.10.6, with version 0.10.6.1 released as the patched version. The vulnerability was published on July 2, 2026, by the xrdp maintainers and carries a CVSS v3.1 base score of 6.5 (Moderate) (GitHub Advisory).
The root cause is classified as CWE-125 (Out-of-bounds Read). During the RDP connection sequence, xrdp's parser fails to perform sufficient length validation before reading specific data fields from the network stream when processing Client Control PDUs. A remote, unauthenticated attacker can send a specially crafted, truncated Client Control PDU to trigger out-of-bounds memory reads in the xrdp process. No authentication or user interaction is required, and the attack is conducted entirely over the network (GitHub Advisory).
Successful exploitation can result in termination of the affected xrdp worker process (Denial of Service) and limited, low-severity memory disclosure (Confidentiality: Low). Because xrdp forks a new process for each incoming connection by default, a crash of a single worker process is unlikely to bring down the entire xrdp service, limiting the availability impact. Integrity is not affected (GitHub Advisory).
/var/log/xrdp.log or /var/log/syslog referencing xrdp worker process crashes.The xrdp maintainers have released version 0.10.6.1 as the patched release, which addresses this vulnerability. Administrators should upgrade to xrdp 0.10.6.1 or later as the primary remediation. As a temporary workaround, restricting access to the xrdp port (default 3389/TCP) via firewall rules to trusted IP ranges can reduce exposure until patching is feasible. Fedora users can apply the updated package available through Fedora's security updates (GitHub Advisory, Linux Security).
The vulnerability was reported by security researcher TristanInSec and published by xrdp maintainer metalefty via a GitHub Security Advisory on July 2, 2026. Coverage has appeared on Linux-focused security news outlets including LinuxSecurity.com and pro-linux.de, as well as FreeBSD ports tracking via FreshPorts. No significant broader media coverage or notable social media discussion has been identified beyond routine Linux security update announcements (GitHub Advisory, Linux Security).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."