Freerdp: Out-of-bounds read in glyph_cache_get via crafted glyph fragments (CVE-2026-55564)
FreeRDP contains an out-of-bounds read vulnerability in the glyph_cache_get function triggered by crafted glyph fragments. This flaw can lead to information disclosure, application crashes causing denial of service, or potentially arbitrary code execution. Multiple versions of FreeRDP, including various Ubuntu package versions, are affected. A patch is available in updated FreeRDP packages for supported Ubuntu releases.
AI Analysis
Technical Summary
CVE-2026-55564 is an out-of-bounds read vulnerability in FreeRDP's glyph_cache_get function caused by specially crafted glyph fragments. This vulnerability allows an attacker to read memory outside the intended bounds, which may result in sensitive information disclosure, application crashes, or arbitrary code execution. The issue affects multiple FreeRDP versions distributed across various Ubuntu releases. Ubuntu has released patched versions of FreeRDP packages to address this vulnerability.
Potential Impact
An attacker exploiting this vulnerability could obtain sensitive information, cause FreeRDP to crash leading to denial of service, or execute arbitrary code. The CVSS score of 5.4 (medium severity) reflects the potential for information disclosure and limited code execution impact without requiring privileges but needing user interaction.
Mitigation Recommendations
A patch is available. Ubuntu has released updated FreeRDP packages (version 3.30.0+dfsg-0ubuntu0.26.04.1 and similar for other supported releases) that fix this vulnerability. Users should apply standard system updates to install these patched versions to remediate the issue.
Freerdp: Out-of-bounds read in glyph_cache_get via crafted glyph fragments (CVE-2026-55564)
Description
FreeRDP contains an out-of-bounds read vulnerability in the glyph_cache_get function triggered by crafted glyph fragments. This flaw can lead to information disclosure, application crashes causing denial of service, or potentially arbitrary code execution. Multiple versions of FreeRDP, including various Ubuntu package versions, are affected. A patch is available in updated FreeRDP packages for supported Ubuntu releases.
CVSS v3.1
Score 5.4medium
Affected software
pkg:deb/ubuntu/[email protected]~git20140921.1.440916e+dfsg1-5ubuntu1.4?arch=source&distro=xenialpkg:deb/ubuntu/[email protected]+dfsg1-0ubuntu0.18.04.4+esm6?arch=source&distro=esm-infra/bionicpkg:deb/ubuntu/[email protected]~git20140921.1.440916e+dfsg1-15ubuntu1.18.04.2?arch=source&distro=bionicpkg:deb/ubuntu/[email protected]+dfsg1-0ubuntu0.20.04.2+esm4?arch=source&distro=esm-infra/focalpkg:deb/ubuntu/[email protected]+dfsg1-3ubuntu2.11?arch=source&distro=jammypkg:deb/ubuntu/[email protected]+dfsg-0ubuntu0.24.04.1?arch=source&distro=noblepkg:deb/ubuntu/[email protected]+dfsg1-1ubuntu0.1~esm6?arch=source&distro=esm-apps/noblepkg:deb/ubuntu/[email protected]+dfsg-2ubuntu0.5?arch=source&distro=questingpkg:deb/ubuntu/[email protected]+dfsg-0ubuntu0.26.04.1?arch=source&distro=resoluteRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-55564 is an out-of-bounds read vulnerability in FreeRDP's glyph_cache_get function caused by specially crafted glyph fragments. This vulnerability allows an attacker to read memory outside the intended bounds, which may result in sensitive information disclosure, application crashes, or arbitrary code execution. The issue affects multiple FreeRDP versions distributed across various Ubuntu releases. Ubuntu has released patched versions of FreeRDP packages to address this vulnerability.
Potential Impact
An attacker exploiting this vulnerability could obtain sensitive information, cause FreeRDP to crash leading to denial of service, or execute arbitrary code. The CVSS score of 5.4 (medium severity) reflects the potential for information disclosure and limited code execution impact without requiring privileges but needing user interaction.
Mitigation Recommendations
A patch is available. Ubuntu has released updated FreeRDP packages (version 3.30.0+dfsg-0ubuntu0.26.04.1 and similar for other supported releases) that fix this vulnerability. Users should apply standard system updates to install these patched versions to remediate the issue.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- UBUNTU-CVE-2026-55564
- Osv Schema Version
- 1.7.0
- Ecosystems
- ["Ubuntu:16.04:LTS","Ubuntu:Pro:18.04:LTS","Ubuntu:18.04:LTS","Ubuntu:Pro:20.04:LTS","Ubuntu:22.04:LTS","Ubuntu:24.04:LTS","Ubuntu:Pro:24.04:LTS","Ubuntu:25.10","Ubuntu:26.04:LTS"]
Threat ID: 6a5e7a702a4a8d59899de947
Added to database: 07/20/2026, 19:43:44 UTC
Last enriched: 08/21/2026, 17:13:48 UTC
Last updated: 09/13/2026, 10:01:31 UTC
Views: 39
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.