{"id":"CVE-2026-57156","aliases":["GHSA-v5wf-j8j4-77h7"],"url":"https://o3.security/vulnerability/CVE-2026-57156","summary":"FreeRDP: Integer overflow leading to heap buffer overflow in Orders Delta Points parsing","details":"FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0 on 32-bit builds, FreeRDP clients contain an integer overflow in update_read_delta_points in libfreerdp/core/orders.c when multiplying an attacker-controlled point count by sizeof(DELTA_POINT), allowing a malicious RDP peer to allocate an undersized heap buffer and then write beyond it during initialization. This issue is fixed in version 3.28.0.","published":"2026-07-10T19:52:25.553Z","modified":"2026-08-12T10:57:06.673832499Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":{"url":"https://github.com/FreeRDP/FreeRDP/commit/487f35daccb36a6224e530dcd8fa60850825f823","label":"FreeRDP/FreeRDP@487f35d"},"references":[{"type":"WEB","url":"https://github.com/FreeRDP/FreeRDP/releases/tag/3.28.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/57xxx/CVE-2026-57156.json"},{"type":"ADVISORY","url":"https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v5wf-j8j4-77h7"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57156"},{"type":"FIX","url":"https://github.com/FreeRDP/FreeRDP/commit/487f35daccb36a6224e530dcd8fa60850825f823"},{"type":"FIX","url":"https://github.com/FreeRDP/FreeRDP/pull/12938"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T10:57:06.673832499Z"}}