-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4759-1                [email protected]
https://www.debian.org/lts/security/                          Abhijith PA
August 29, 2026                               https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package        : xrdp
Version        : 0.9.21.1-1~deb11u4 0.9.21.1-1+deb12u3
CVE ID         : CVE-2026-32105 CVE-2026-32107 CVE-2026-32623 CVE-2026-32624 
                 CVE-2026-33516 CVE-2026-33689 CVE-2026-41252 CVE-2026-41521 
                 CVE-2026-44178 CVE-2026-44978 CVE-2026-54538 CVE-2026-55238 
                 CVE-2026-55639 CVE-2026-55645

Several vulnerabilities were discovered in xrdp, a Remote Desktop
Protocol (RDP) server. 

CVE-2026-32105

    modify encrypted traffic in transit without detection

CVE-2026-32107

    improper privilege management allow attacker to escalate
    privileges to root and execute arbitrary code.

CVE-2026-32623

    heap-based buffer overflow vulnerability

CVE-2026-32624

    heap-based buffer overflow vulnerability

CVE-2026-33516

    out-of-bounds read vulnerability

CVE-2026-33689

    out-of-bounds read vulnerability

CVE-2026-41252

    missing bounds check in xrdp, which allows a heap-based buffer
    overflow

CVE-2026-41521

    integer overflow vulnerability

CVE-2026-44178

    heap-based buffer overflow vulnerability

CVE-2026-44978

    heap out-of-bounds read vulnerability

CVE-2026-54538

    sending a specially crafted packet that forces the process into an
    infinite, CPU-bound loop

CVE-2026-55238

    Denial of Service

CVE-2026-55639

    exploit by specially crafted RDP malformed data and read
    out-of-bound data block.

CVE-2026-55645

    out-of-bounds memory reads

For Debian 11 bullseye, these problems have been fixed in version
0.9.21.1-1~deb11u4.

For Debian 12 bookworm, these problems have been fixed in version
0.9.21.1-1+deb12u3.

We recommend that you upgrade your xrdp packages.

For the detailed security status of xrdp please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/xrdp

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----

iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqSVYQACgkQhj1N8u2c
KO82jw//ZP0NpKM1RDfTvXpRL4qA9DyYsRo0icsKlsUdpyWzbSwtDQpPL4MKEset
tLCj7w323lWZRz6oAOQR7LZtiHXKUHVECG5wBGge6Gm7nKxW7j4KW3L5hFhMgHy4
USDAeLRJFvciD/i8m2QoECopyqBeDzNzFiVO1wOq5llNVw18JcQj/FraoZx8c5Xz
5rjq/A9X3AeUxTYaGSAhvbo65+pDpbO6128QB5hKCFXjkEpKFzXY36vC+6VlaDtO
rWb1woZ8pQWlbpTT21G6uAuQTyQIY3ZK7ilkXX4myhe6gYuEsAOddd1EWzVMFfz4
3zMKQDAdW/ZrgrbJcrM9fQ1lwIiLM1pmJNQTLcnDdAZpnGaN7eveEb1hbt8pZ/oa
7aD45ivcQ4VUYp3eecfljYEJ7RJEYrGv/0E/avTIHUI+7Z16G6g1GK4bg17pgiNF
NHcp37XkVq2aLQx6vqsrfObc30mb54ewIrBGnIxHxDPbnUGtnNqEx80o80qrqsGo
fkhqXWHmavvmV23Vh6/BcVsc9HX8K+QGPdiIGkW/k/UoP8HhjkqRl+JVxOjCO7hq
XNfoRdfOHSq4lCK6bcvQqb3tX/u17qOIiOiUHulS7JZ1ypIj7hyBCxFtW2D/kk4L
NwVdvgS6BFzczeMmp/KqjKE6kSXGCzTTHBnW98Q6Iq5GrP8JJRQ=
=rM46
-----END PGP SIGNATURE-----

Reply via email to