Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-63117

Опубликовано: 19 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the bs calculation in rdpsnd_server_select_format in channels/rdpsnd/server/rdpsnd_main.c equal zero. The subsequent out_frames modulo bs operation raises SIGFPE and terminates the server-side rdpsnd channel process. This vulnerability fixed in 3.28.0.

A flaw was found in FreeRDP, a free implementation of the Remote Desktop Protocol. An authenticated Remote Desktop Protocol (RDP) client can trigger a denial of service by sending a specially crafted DVI ADPCM frame. By advertising specific nBlockAlign and nChannels values, a division-by-zero error occurs in the rdpsnd_server_select_format function. This vulnerability leads to the termination of the server-side rdpsnd channel process, causing a denial of service.

Отчет

A divide-by-zero flaw was found in FreeRDP's rdpsnd audio channel server implementation. An authenticated remote RDP client can send malformed DVI ADPCM audio parameters (nBlockAlign=8, nChannels=2) during format selection in rdpsnd_server_select_format. This triggers an unhandled SIGFPE signal when calculating audio frames, crashing the server-side rdpsnd process and resulting in a denial of service for remote desktop audio capabilities.

Меры по смягчению последствий

To mitigate this issue, administrators can disable audio redirection on the FreeRDP server configuration if remote audio support is not strictly required.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10freerdpFix deferred
Red Hat Enterprise Linux 6freerdpNot affected
Red Hat Enterprise Linux 7freerdpFix deferred
Red Hat Enterprise Linux 8freerdpFix deferred
Red Hat Enterprise Linux 9freerdpFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-369
https://bugzilla.redhat.com/show_bug.cgi?id=2519821FreeRDP: FreeRDP: Denial of Service via ADPCM frame size calculation

EPSS

Процентиль: 32%
0.00389
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
16 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the `bs` calculation in rdpsnd_server_select_format in channels/rdpsnd/server/rdpsnd_main.c equal zero. The subsequent out_frames modulo `bs` operation raises SIGFPE and terminates the server-side rdpsnd channel process. This vulnerability fixed in 3.28.0.

CVSS3: 6.5
nvd
16 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advertise DVI ADPCM with nBlockAlign equal to 8 and nChannels equal to 2 to make the `bs` calculation in rdpsnd_server_select_format in channels/rdpsnd/server/rdpsnd_main.c equal zero. The subsequent out_frames modulo `bs` operation raises SIGFPE and terminates the server-side rdpsnd channel process. This vulnerability fixed in 3.28.0.

CVSS3: 6.5
debian
16 дней назад

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...

EPSS

Процентиль: 32%
0.00389
Низкий

6.5 Medium

CVSS3

Уязвимость CVE-2026-63117