CVE-2026-23530 | FreeRDP up to 3.20.x freerdp_bitmap_decompress_planar nSrcWidth/nSrcHeight heap-based overflow (GHSA-r4hv-852m-fq7p)
A vulnerability marked as critical has been reported in FreeRDP up to 3.20.x. Affected by this issue is the function freerdp_bitmap_decompress_planar. Performing a manipulation of the argument nSrcWidth/nSrcHeight results in heap-based buffer overflow.
This vulnerability was named CVE-2026-23530. The attack may be initiated remotely. There is no available exploit.
It is suggested to upgrade the affected component.