CVE Vulnerabilities

CVE-2026-40254

Off-by-one Error

Published: Apr 24, 2026 | Modified: Jun 17, 2026
CVSS 3.x
6.1
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
6.1 MODERATE
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

FreeRDP is a free implementation of the Remote Desktop Protocol. Versions prior to 3.25.0 have an off-by-one in the path traversal filter in channels/drive/client/drive_file.c. The contains_dotdot() function catches ../ and .. mid-path but misses .. when its the last component with no trailing separator. A rogue RDP server can read, list, or write files one directory above the clients shared folder through RDPDR requests. This requires the victim to connect with drive redirection enabled. Version 3.25.0 patches the issue.

Weakness

A product calculates or uses an incorrect maximum or minimum value that is 1 more, or 1 less, than the correct value.

Affected Software

NameVendorStart VersionEnd Version
FreerdpFreerdp*3.25.0 (excluding)
FreerdpUbuntuesm-infra/xenial*
Freerdp3Ubuntunoble*
Freerdp3Ubuntuquesting*
Freerdp3Ubunturesolute*
Freerdp3Ubuntuupstream*

Potential Mitigations

References