Critical xrdp Vulnerabilities Affecting Ubuntu Systems

Critical xrdp Vulnerabilities Affecting Ubuntu Systems

First seen 25 Jun 2026, 18:10 UTC UbuntuLinuxsecurity 94% similarity 72.0
Share:

Article Content

Browse articles
ThreatCluster

Multiple vulnerabilities were identified in xrdp, an open-source RDP server, impacting Ubuntu 24.04 LTS. CVE-2025-68670 allows unauthenticated attackers to crash xrdp, leading to denial of service or arbitrary code execution. CVE-2024-39917 permits unlimited login attempts, while CVE-2023-42822 involves out-of-bounds reading due to improper bounds checking. Additionally, CVE-2023-40184 allows bypassing OS-level session restrictions. The vulnerabilities were disclosed on 2026-06-25, with patches available for affected systems. Users are advised to update their xrdp installations promptly to mitigate these risks.

Key Points: • xrdp vulnerabilities could lead to denial of service and arbitrary code execution. • Ubuntu 24.04 LTS is specifically affected by these vulnerabilities. • Immediate updates are recommended to secure systems against these threats.

ThreatCluster AI

Timeline

2023-08-30
CVE-2023-40184 published
CVE-2023-40184 was published, allowing attackers to bypass OS-level session restrictions.
N/A
2023-09-27
CVE-2023-42822 published
CVE-2023-42822 was published, revealing an out-of-bounds reading issue in xrdp.
N/A
2024-07-12
CVE-2024-39917 published
CVE-2024-39917 was published, detailing a flaw that allows unlimited login attempts in xrdp.
N/A
2026-01-27
CVE-2025-68670 published
CVE-2025-68670 was published, highlighting a critical vulnerability in xrdp that allows denial of service or code execution.
N/A
2026-06-25
xrdp vulnerabilities disclosed
Multiple vulnerabilities in xrdp were announced, affecting Ubuntu 24.04 LTS and allowing denial of service and code execution.
Ubuntu
2026-06-25
Security advisory published
Linuxsecurity published an advisory detailing the vulnerabilities and urging users to update their systems.
Linuxsecurity

Community

Browse all →