CVE-2026-54538

NameCVE-2026-54538
Descriptionxrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properly validate the totalLength field within the RDP protocol control header during packet reception. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted packet that forces the xrdp process or thread into an infinite, CPU-bound loop. Because the internal pointer fails to advance and the deadlock prevention mechanism is bypassed for specific protocol data unit types, the process consumes excessive CPU resources indefinitely. This can render the xrdp service unavailable and potentially lead to system-wide resource exhaustion if multiple malicious connections are established. This issue has been fixed in version 0.10.6.1.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
xrdp (PTS)bullseye0.9.21.1-1~deb11u1vulnerable
bullseye (security)0.9.21.1-1~deb11u3vulnerable
bookworm, bookworm (security)0.9.21.1-1+deb12u2vulnerable
trixie (security), trixie0.10.1-3.1+deb13u1vulnerable
sid0.10.6.1-2fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
xrdpsourceexperimental0.10.6.1-1
xrdpsource(unstable)0.10.6.1-2

Notes

https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-9j3q-9mvw-qv7j

Search for package or bug name: Reporting problems