-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Thu, 13 Aug 2026 14:14:56 +0530 Source: xrdp Architecture: source Version: 0.10.1-3.1+deb13u2 Distribution: trixie-security Urgency: high Maintainer: Debian Remote Maintainers <debian-remote@lists.debian.org> Changed-By: Abhijith PA <abhijith@debian.org> Closes: 1134339 Changes: xrdp (0.10.1-3.1+deb13u2) trixie-security; urgency=high . * Non-maintainer upload. * CVE-CVE-2026-32105: modify encrypted traffic in transit without detection (Closes: #1134339) * CVE-2026-32107: improper privilege management allow attacker to escalate privileges to root and execute arbitrary code. * CVE-2026-32623: heap-based buffer overflow vulnerability * CVE-2026-32624: heap-based buffer overflow vulnerability * CVE-2026-33145: authenticated remote user to execute arbitrary commands * CVE-2026-33516: out-of-bounds read vulnerability * CVE-2026-33689: out-of-bounds read vulnerability * CVE-2026-35512: a heap-based buffer overflow * CVE-2026-41252: missing bounds check in xrdp, which allows a heap-based buffer overflow * CVE-2026-41521: nteger overflow vulnerability * CVE-2026-42218: a timing side-channel vulnerability in the login interface * CVE-2026-44178: heap-based buffer overflow vulnerability * CVE-2026-44978: heap out-of-bounds read vulnerability * CVE-2026-54538: sending a specially crafted packet that forces the process into an infinite, CPU-bound loop * CVE-2026-55238: Denial of Service * CVE-2026-55639: exploit by specially crafted RDP malformed data and read out-of-bound data block. * CVE-2026-55645: out-of-bounds memory reads Checksums-Sha1: 16a173654e8eecabd74185fd9babe095625298d5 1944 xrdp_0.10.1-3.1+deb13u2.dsc 4ee4b587fdea7dca399be3a25d93f746825e7053 2402893 xrdp_0.10.1.orig.tar.gz 32b3163e43eddff5b323209e7f93b154121e330e 52304 xrdp_0.10.1-3.1+deb13u2.debian.tar.xz 6672254ce3c192c7220b1aaf28e388f9412df66c 6471 xrdp_0.10.1-3.1+deb13u2_source.buildinfo Checksums-Sha256: 00546ec03e6f5fd5d13e73644f5f27de4c2d443e80423356412c3c234300aec7 1944 xrdp_0.10.1-3.1+deb13u2.dsc a2535f4420080630e20f0639c30c244170003ab998cc82d7913c2be856622f83 2402893 xrdp_0.10.1.orig.tar.gz 00d1c87fc76920120e3888d2264c94504a787b9fc65327a30343c79ec2b5ec25 52304 xrdp_0.10.1-3.1+deb13u2.debian.tar.xz eca892eb1fd99331ae7b97c0f8221f0cf81170cb0adfd239ebfbab2c8eae3c37 6471 xrdp_0.10.1-3.1+deb13u2_source.buildinfo Files: 09bf5b92235434a301b8680367cda38e 1944 net optional xrdp_0.10.1-3.1+deb13u2.dsc 65edae2e80bcaa9b8fa6b8abd60fbe0e 2402893 net optional xrdp_0.10.1.orig.tar.gz 8636019603f5065bd8d99b46475a8426 52304 net optional xrdp_0.10.1-3.1+deb13u2.debian.tar.xz 08b2c2a1125974b903e34c501d73428a 6471 net optional xrdp_0.10.1-3.1+deb13u2_source.buildinfo -----BEGIN PGP SIGNATURE----- iQEzBAEBCgAdFiEExq6D0hxncEPaPayX+GQ1dHE8m64FAmqNpNYACgkQ+GQ1dHE8 m67GlwgAm5mNENQ4zN6oevr4mA2etcc+ABgLrDmn1Z+2R+1JWjC6mYFVEVtUKi9h 08FCr1xo8hr3c9qdknQtqlWB6sbCJQxMulI3OOSS/X0p3/EFtD7Srw65eBNEW6HI 1H760OwvrMYChW334kXecOtZaVZYFiyfXGA5GbehOD9p1VESCTQOBxe/WyJjI8Q5 YgQ3ygzg870EyHTYmacwBW5z83wZIs43m340ddvbWaiFRFgaXhJpVB2tSrP8QkuV FtfGjJfLpCf5mIcpqTRbvYb9HYaIg8V1Gd/S6Ko/fkdNjKQb2394B3SGQZTeVBRH 0P41d3a5NKaIVIzMc4SHT49t+V830A== =5Wov -----END PGP SIGNATURE-----