MEDIUMVulnerability

CVE-2026-85090

FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a RFX_AVC444_BITMAP_STREAM with specific frame geometry to trigger an out-of-bounds memory read past the allocated luma plane.

Properties

severity
MEDIUM
score
5.4
epss_score
0.00314
cve_id
CVE-2026-85090
signal_observed_at
2026-09-15T21:12:51+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
published_at
2026-09-03T13:06:20.430
last_modified
2026-09-09T19:22:08.110
epss_percentile
0.24225

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Out-of-bounds Read

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85090 — Ninja Signal Threat Intelligence | Ninja Signal