-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4759-1 [email protected]
https://www.debian.org/lts/security/ Abhijith PA
August 29, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : xrdp
Version : 0.9.21.1-1~deb11u4 0.9.21.1-1+deb12u3
CVE ID : CVE-2026-32105 CVE-2026-32107 CVE-2026-32623 CVE-2026-32624
CVE-2026-33516 CVE-2026-33689 CVE-2026-41252 CVE-2026-41521
CVE-2026-44178 CVE-2026-44978 CVE-2026-54538 CVE-2026-55238
CVE-2026-55639 CVE-2026-55645
Several vulnerabilities were discovered in xrdp, a Remote Desktop
Protocol (RDP) server.
CVE-2026-32105
modify encrypted traffic in transit without detection
CVE-2026-32107
improper privilege management allow attacker to escalate
privileges to root and execute arbitrary code.
CVE-2026-32623
heap-based buffer overflow vulnerability
CVE-2026-32624
heap-based buffer overflow vulnerability
CVE-2026-33516
out-of-bounds read vulnerability
CVE-2026-33689
out-of-bounds read vulnerability
CVE-2026-41252
missing bounds check in xrdp, which allows a heap-based buffer
overflow
CVE-2026-41521
integer overflow vulnerability
CVE-2026-44178
heap-based buffer overflow vulnerability
CVE-2026-44978
heap out-of-bounds read vulnerability
CVE-2026-54538
sending a specially crafted packet that forces the process into an
infinite, CPU-bound loop
CVE-2026-55238
Denial of Service
CVE-2026-55639
exploit by specially crafted RDP malformed data and read
out-of-bound data block.
CVE-2026-55645
out-of-bounds memory reads
For Debian 11 bullseye, these problems have been fixed in version
0.9.21.1-1~deb11u4.
For Debian 12 bookworm, these problems have been fixed in version
0.9.21.1-1+deb12u3.
We recommend that you upgrade your xrdp packages.
For the detailed security status of xrdp please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/xrdp
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqSVYQACgkQhj1N8u2c
KO82jw//ZP0NpKM1RDfTvXpRL4qA9DyYsRo0icsKlsUdpyWzbSwtDQpPL4MKEset
tLCj7w323lWZRz6oAOQR7LZtiHXKUHVECG5wBGge6Gm7nKxW7j4KW3L5hFhMgHy4
USDAeLRJFvciD/i8m2QoECopyqBeDzNzFiVO1wOq5llNVw18JcQj/FraoZx8c5Xz
5rjq/A9X3AeUxTYaGSAhvbo65+pDpbO6128QB5hKCFXjkEpKFzXY36vC+6VlaDtO
rWb1woZ8pQWlbpTT21G6uAuQTyQIY3ZK7ilkXX4myhe6gYuEsAOddd1EWzVMFfz4
3zMKQDAdW/ZrgrbJcrM9fQ1lwIiLM1pmJNQTLcnDdAZpnGaN7eveEb1hbt8pZ/oa
7aD45ivcQ4VUYp3eecfljYEJ7RJEYrGv/0E/avTIHUI+7Z16G6g1GK4bg17pgiNF
NHcp37XkVq2aLQx6vqsrfObc30mb54ewIrBGnIxHxDPbnUGtnNqEx80o80qrqsGo
fkhqXWHmavvmV23Vh6/BcVsc9HX8K+QGPdiIGkW/k/UoP8HhjkqRl+JVxOjCO7hq
XNfoRdfOHSq4lCK6bcvQqb3tX/u17qOIiOiUHulS7JZ1ypIj7hyBCxFtW2D/kk4L
NwVdvgS6BFzczeMmp/KqjKE6kSXGCzTTHBnW98Q6Iq5GrP8JJRQ=
=rM46
-----END PGP SIGNATURE-----