{"id":"DEBIAN-CVE-2026-35512","details":"xrdp is an open source RDP server. Versions through 0.10.5 have a heap-based buffer overflow in the EGFX (graphics dynamic virtual channel) implementation due to insufficient validation of client-controlled size parameters, allowing an out-of-bounds write via crafted PDUs. Pre-authentication exploitation can crash the process, while post-authentication exploitation may achieve remote code execution. This issue has been fixed in version 0.10.6. If users are unable to immediately update, they should run xrdp as a non-privileged user (default since 0.10.2) to limit the impact of successful exploitation.","modified":"2026-08-27T23:05:58.649598069Z","published":"2026-04-17T21:16:33.297Z","upstream":["CVE-2026-35512"],"references":[{"type":"ADVISORY","url":"https://security-tracker.debian.org/tracker/CVE-2026-35512"}],"affected":[{"package":{"name":"xrdp","ecosystem":"Debian:13","purl":"pkg:deb/debian/xrdp?arch=source&distro=trixie"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.1-3.1+deb13u2"}]}],"versions":["0.10.1-3.1","0.10.1-3.1+deb13u1"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-35512.json"}},{"package":{"name":"xrdp","ecosystem":"Debian:14","purl":"pkg:deb/debian/xrdp?arch=source&distro=forky"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"0.10.6-1"}]}],"versions":["0.10.1-3.1","0.10.1-4","0.10.1-4.1","0.10.2-1","0.10.2-2","0.10.4.1-1","0.10.4.1-2","0.10.5-1","0.10.5-2","0.10.5-3","0.10.5-4","0.10.5-5"],"ecosystem_specific":{"urgency":"not yet assigned"},"database_specific":{"source":"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-35512.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"}]}