Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-68580

Опубликовано: 02 авг. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

EPSS

Процентиль: 15%
0.00238
Низкий

7.5 High

CVSS3

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.5
redhat
4 дня назад

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

CVSS3: 7.5
debian
4 дня назад

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the ...

CVSS3: 7.5
github
4 дня назад

FreeRDP before 3.29.0 contains integer overflow vulnerabilities in the audio input redirection channel (audin) across ALSA, sndio, WinMM, and OpenSL ES backends that fail to validate the FramesPerPacket parameter from RDP servers. Attackers can supply a malicious FramesPerPacket value causing allocation size wraparound, resulting in heap-based buffer overflow on ALSA or denial of service on all platforms.

CVSS3: 7.5
fstec
17 дней назад

Уязвимость RDP-клиента FreeRDP, связанная с переполнением буфера в динамической памяти, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 15%
0.00238
Низкий

7.5 High

CVSS3

Дефекты

CWE-122