Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2026-55238

CVE-2026-55238: Neutrinolabs Xrdp DOS Vulnerability

CVE-2026-55238 is a denial of service flaw in Neutrinolabs Xrdp affecting versions 0.10.6 and prior. Attackers can crash the service via malformed RDP packets. This article covers technical details, impact, and fixes.

Published:

CVE-2026-55238 Overview

CVE-2026-55238 is an out-of-bounds read vulnerability in xrdp, an open source Remote Desktop Protocol (RDP) server maintained by neutrinolabs. The flaw resides in the capability negotiation phase of the RDP Confirm Active Protocol Data Unit (PDU) parser, which fails to perform sufficient length validation on specific capability sets. A remote, unauthenticated attacker can send a specially crafted RDP packet containing malformed capability data to trigger the condition. The result is an out-of-bounds memory read that terminates the connection process, producing a limited denial-of-service condition. All versions of xrdp up to and including 0.10.6 are affected, and the issue is tracked as [CWE-126: Buffer Over-read].

Critical Impact

Unauthenticated network attackers can crash individual xrdp connection handlers by sending malformed RDP capability data, though the forking service model prevents full daemon shutdown.

Affected Products

  • neutrinolabs xrdp versions 0.10.6 and prior
  • Linux distributions packaging vulnerable xrdp builds
  • Remote desktop gateways relying on xrdp for RDP session brokering

Discovery Timeline

  • 2026-07-20 - CVE-2026-55238 published to NVD
  • 2026-07-22 - Last updated in NVD database

Technical Details for CVE-2026-55238

Vulnerability Analysis

The vulnerability occurs during RDP capability negotiation, when the client transmits a Confirm Active PDU to the xrdp server. This PDU carries a list of capability sets describing supported features such as bitmap, order, and pointer capabilities. The xrdp parser reads the capability set length fields from attacker-controlled data without validating them against the actual bounds of the received packet buffer.

When an attacker supplies malformed capability metadata, the parser advances its read pointer past the end of the allocated buffer. The subsequent memory access constitutes a classified buffer over-read under [CWE-126]. The affected xrdp process crashes, terminating the RDP session. Because xrdp forks a dedicated child process per inbound connection, the parent listener continues accepting new connections. The impact is therefore constrained to session-level denial of service rather than full daemon outage.

Root Cause

The root cause is missing bounds validation in the Confirm Active PDU capability set parser. The code trusts length values embedded in the client-supplied packet rather than verifying that each capability set fits within the remaining buffer length. This category of defect is characteristic of protocol parsers that mirror on-wire structures directly onto memory without defensive length checks.

Attack Vector

Exploitation requires network reachability to the xrdp listener, typically TCP port 3389. No authentication or user interaction is required, since the vulnerable parsing occurs before session credentials are validated. The attacker completes the initial RDP connection handshake, then transmits a crafted Confirm Active PDU containing a capability set with a length field that extends beyond the packet body. Repeatedly opening new connections and delivering the malformed PDU forces the server to spawn and crash child processes, consuming CPU and file descriptor resources.

No public proof-of-concept exploit is currently available. Technical detail is limited to the vendor advisory published at GitHub Security Advisory GHSA-mg8j-x9rw-9xv3.

Detection Methods for CVE-2026-55238

Indicators of Compromise

  • Repeated xrdp child process crashes recorded in system logs such as /var/log/xrdp.log or journalctl -u xrdp
  • SIGSEGV termination events for the xrdp binary in kernel or auditd logs
  • Bursts of short-lived RDP connections from a single source IP that disconnect during capability negotiation

Detection Strategies

  • Inspect RDP traffic for Confirm Active PDUs whose declared capability set lengths exceed the remaining PDU length
  • Correlate high volumes of TCP 3389 connections with elevated rates of xrdp process exits
  • Monitor host telemetry for unusual fork and crash cycles associated with the xrdp service account

Monitoring Recommendations

  • Forward xrdp service logs and process crash events to a centralized logging or SIEM platform for correlation
  • Alert on threshold breaches in xrdp child process restart counts per minute
  • Track source IPs establishing many partial RDP handshakes without completing authentication

How to Mitigate CVE-2026-55238

Immediate Actions Required

  • Upgrade xrdp to version 0.10.6.1 or later on all affected hosts
  • Restrict inbound access to TCP port 3389 using host or perimeter firewalls, allowing only trusted management networks
  • Place xrdp behind a VPN or zero-trust access broker to remove direct internet exposure

Patch Information

The issue is fixed in xrdp version 0.10.6.1. Administrators should install the update from the official release at GitHub Release v0.10.6.1 or from the security advisory at GitHub Security Advisory GHSA-mg8j-x9rw-9xv3. Downstream distribution maintainers should backport the fix into supported 0.10.x packages.

Workarounds

  • Limit RDP exposure by binding xrdp to internal interfaces only
  • Enforce network-level access controls that require VPN authentication before RDP negotiation
  • Rate-limit new TCP 3389 connections per source IP at the firewall to reduce crash-loop amplification
bash
# Restrict xrdp exposure with iptables until patching completes
iptables -A INPUT -p tcp --dport 3389 -s 10.0.0.0/8 -j ACCEPT
iptables -A INPUT -p tcp --dport 3389 -j DROP

# Verify installed xrdp version after upgrade
xrdp --version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.