LIVE · cybersecurity feed
Live wire
cve recordhigh

CVE-2026-54538

neutrinolabs · xrdp

Published
CVSS7.5
Severityhigh
WeaknessCWE-835
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

xrdp is an open source RDP server. In versions 0.10.6 and prior, a n issue was discovered where the software fails to properly validate the totalLength field within the RDP protocol control header during packet reception. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted packet that forces the xrdp process or thread into an infinite, CPU-bound loop. Because the internal pointer fails to advance and the deadlock prevention mechanism is bypassed for specific protocol data unit types, the process consumes excessive CPU resources indefinitely. This can render the xrdp service unavailable and potentially lead to system-wide resource exhaustion if mul

References

← Back to the CVE Tracker

Our coverage of CVE-2026-54538

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-54538.