|
|
Log in / Subscribe / Register

Debian alert DLA-4759-1 (xrdp)

From:  Abhijith PA <abhijith@debian.org>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4759-1] xrdp security update
Date:  Sat, 29 Aug 2026 09:14:09 +0530
Message-ID:  <apJViWcpGtb6s3u4@debian.org>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4759-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Abhijith PA August 29, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : xrdp Version : 0.9.21.1-1~deb11u4 0.9.21.1-1+deb12u3 CVE ID : CVE-2026-32105 CVE-2026-32107 CVE-2026-32623 CVE-2026-32624 CVE-2026-33516 CVE-2026-33689 CVE-2026-41252 CVE-2026-41521 CVE-2026-44178 CVE-2026-44978 CVE-2026-54538 CVE-2026-55238 CVE-2026-55639 CVE-2026-55645 Several vulnerabilities were discovered in xrdp, a Remote Desktop Protocol (RDP) server. CVE-2026-32105 modify encrypted traffic in transit without detection CVE-2026-32107 improper privilege management allow attacker to escalate privileges to root and execute arbitrary code. CVE-2026-32623 heap-based buffer overflow vulnerability CVE-2026-32624 heap-based buffer overflow vulnerability CVE-2026-33516 out-of-bounds read vulnerability CVE-2026-33689 out-of-bounds read vulnerability CVE-2026-41252 missing bounds check in xrdp, which allows a heap-based buffer overflow CVE-2026-41521 integer overflow vulnerability CVE-2026-44178 heap-based buffer overflow vulnerability CVE-2026-44978 heap out-of-bounds read vulnerability CVE-2026-54538 sending a specially crafted packet that forces the process into an infinite, CPU-bound loop CVE-2026-55238 Denial of Service CVE-2026-55639 exploit by specially crafted RDP malformed data and read out-of-bound data block. CVE-2026-55645 out-of-bounds memory reads For Debian 11 bullseye, these problems have been fixed in version 0.9.21.1-1~deb11u4. For Debian 12 bookworm, these problems have been fixed in version 0.9.21.1-1+deb12u3. We recommend that you upgrade your xrdp packages. For the detailed security status of xrdp please refer to its security tracker page at: https://security-tracker.debian.org/tracker/xrdp Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE7xPqJqaY/zX9fJAuhj1N8u2cKO8FAmqSVYQACgkQhj1N8u2c KO82jw//ZP0NpKM1RDfTvXpRL4qA9DyYsRo0icsKlsUdpyWzbSwtDQpPL4MKEset tLCj7w323lWZRz6oAOQR7LZtiHXKUHVECG5wBGge6Gm7nKxW7j4KW3L5hFhMgHy4 USDAeLRJFvciD/i8m2QoECopyqBeDzNzFiVO1wOq5llNVw18JcQj/FraoZx8c5Xz 5rjq/A9X3AeUxTYaGSAhvbo65+pDpbO6128QB5hKCFXjkEpKFzXY36vC+6VlaDtO rWb1woZ8pQWlbpTT21G6uAuQTyQIY3ZK7ilkXX4myhe6gYuEsAOddd1EWzVMFfz4 3zMKQDAdW/ZrgrbJcrM9fQ1lwIiLM1pmJNQTLcnDdAZpnGaN7eveEb1hbt8pZ/oa 7aD45ivcQ4VUYp3eecfljYEJ7RJEYrGv/0E/avTIHUI+7Z16G6g1GK4bg17pgiNF NHcp37XkVq2aLQx6vqsrfObc30mb54ewIrBGnIxHxDPbnUGtnNqEx80o80qrqsGo fkhqXWHmavvmV23Vh6/BcVsc9HX8K+QGPdiIGkW/k/UoP8HhjkqRl+JVxOjCO7hq XNfoRdfOHSq4lCK6bcvQqb3tX/u17qOIiOiUHulS7JZ1ypIj7hyBCxFtW2D/kk4L NwVdvgS6BFzczeMmp/KqjKE6kSXGCzTTHBnW98Q6Iq5GrP8JJRQ= =rM46 -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds