CVE-2026-55645
xrdp vulnerability analysis and mitigation

Overview

CVE-2026-55645 is an out-of-bounds read vulnerability in xrdp's Client Control PDU processing that allows a remote, unauthenticated attacker to cause a Denial of Service or potentially read limited memory contents. It affects xrdp versions through 0.10.6, with version 0.10.6.1 released as the patched version. The vulnerability was published on July 2, 2026, by the xrdp maintainers and carries a CVSS v3.1 base score of 6.5 (Moderate) (GitHub Advisory).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read). During the RDP connection sequence, xrdp's parser fails to perform sufficient length validation before reading specific data fields from the network stream when processing Client Control PDUs. A remote, unauthenticated attacker can send a specially crafted, truncated Client Control PDU to trigger out-of-bounds memory reads in the xrdp process. No authentication or user interaction is required, and the attack is conducted entirely over the network (GitHub Advisory).

Impact

Successful exploitation can result in termination of the affected xrdp worker process (Denial of Service) and limited, low-severity memory disclosure (Confidentiality: Low). Because xrdp forks a new process for each incoming connection by default, a crash of a single worker process is unlikely to bring down the entire xrdp service, limiting the availability impact. Integrity is not affected (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing Linux/Unix hosts running xrdp (default port 3389/TCP) using network scanners such as Shodan, Censys, or Nmap, targeting versions ≤ 0.10.6.
  2. Craft malicious PDU: Construct a truncated or malformed Client Control PDU that omits or shortens required data fields, bypassing the expected length validation in xrdp's parser.
  3. Send crafted packet: Establish a TCP connection to the xrdp listener on port 3389 and transmit the crafted PDU during the RDP connection sequence, before authentication is required.
  4. Trigger out-of-bounds read: The xrdp worker process reads beyond the intended buffer boundary, resulting in either a process crash (DoS of that session) or potential exposure of adjacent memory contents (GitHub Advisory).

Indicators of compromise

  • Network: Unusual or repeated TCP connections to port 3389 from external or unexpected IP addresses; connections that terminate abruptly during the RDP handshake phase without completing authentication.
  • Logs: xrdp session logs showing repeated connection attempts followed by abnormal process termination or segmentation fault messages; entries in /var/log/xrdp.log or /var/log/syslog referencing xrdp worker process crashes.
  • Process: Unexpected termination of xrdp child/worker processes (visible via system logs or process monitoring); core dump files generated by xrdp in its working directory.

Mitigation and workarounds

The xrdp maintainers have released version 0.10.6.1 as the patched release, which addresses this vulnerability. Administrators should upgrade to xrdp 0.10.6.1 or later as the primary remediation. As a temporary workaround, restricting access to the xrdp port (default 3389/TCP) via firewall rules to trusted IP ranges can reduce exposure until patching is feasible. Fedora users can apply the updated package available through Fedora's security updates (GitHub Advisory, Linux Security).

Community reactions

The vulnerability was reported by security researcher TristanInSec and published by xrdp maintainer metalefty via a GitHub Security Advisory on July 2, 2026. Coverage has appeared on Linux-focused security news outlets including LinuxSecurity.com and pro-linux.de, as well as FreeBSD ports tracking via FreshPorts. No significant broader media coverage or notable social media discussion has been identified beyond routine Linux security update announcements (GitHub Advisory, Linux Security).

Additional resources


SourceThis report was generated using AI

Related xrdp vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-55626HIGH8
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026
CVE-2026-54538HIGH7.5
  • xrdp logoxrdp
  • cpe:2.3:a:neutrinolabs:xrdp
NoYesJul 20, 2026
CVE-2026-55645MEDIUM6.5
  • xrdp logoxrdp
  • xrdp-debugsource
NoYesJul 20, 2026
CVE-2026-55639MEDIUM5.3
  • xrdp logoxrdp
  • xrdp-debuginfo
NoYesJul 20, 2026
CVE-2026-55238MEDIUM5.3
  • xrdp logoxrdp
  • xrdp
NoYesJul 20, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management